Skip to content

Security: sindresorhus/execa

.github/security.md

Security Policy

To report a security vulnerability, please submit it here.

No AI slop will be accepted.

Not vulnerabilities

  • Command injection through the shell option, or through a command or options that come from untrusted input. Only arguments are escaped.
  • On Windows, a batch file that misuses its arguments, like if "%1" == "". No escaping can prevent this. See Windows escaping.
  • Prototype pollution, except of the top-level options. Node.js itself is not safe from it.

There aren't any published security advisories