depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access
depscope/bugs/npm/cross-spawn
This package has limited bug data (1 entry). Check back later or see the package health page for the full signal.

cross-spawn known bugs

npm

1 known bug in cross-spawn, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.

View package health \u2192Breaking changes \u2192
1
bugs

Known bugs

SeverityAffectedFixed inTitleStatusSource
high7.0.07.0.5
Regular Expression Denial of Service (ReDoS) in cross-spawn
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
fixedosv:GHSA-3xgq-45jj-v275

API access

Get this data programmatically \u2014 free, no authentication.

curl https://depscope.dev/api/bugs/npm/cross-spawn
DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents