To report a security vulnerability, please submit it here.
No AI slop will be accepted.
- Command injection through the
shelloption, or through a command or options that come from untrusted input. Only arguments are escaped. - On Windows, a batch file that misuses its arguments, like
if "%1" == "". No escaping can prevent this. See Windows escaping. - Prototype pollution, except of the top-level options. Node.js itself is not safe from it.