CVE Database
/

CVE-2024-3566

Back to search

CVE-2024-3566

Published: Apr 10, 2024

Modified: Nov 18, 2025

PUBLISHED

Description

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

VendorProductVersions

Node.js

Node.js

affected
* - <= 21.7.2

Go Programming Language

GoLang

affected
*

Haskell Programming Language

Haskel

affected
*

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now