# cross-spawn@7.0.6 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:15:01.000Z
- Files reviewed: 6
- Findings: 2 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/cross-spawn
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package cross-spawn@7.0.6 on Oct 6, 2026. An AI review of 6 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Spawning processes

Finding ID: `NPS-AF45F8FFDC33`

File: `index.js:11`

The module directly uses child_process.spawn and child_process.spawnSync to execute commands. While this is the intended functionality of the cross-spawn package, it represents a capability that could be abused if the package is compromised. The command and arguments are derived from user input/arguments passed to the exported functions.

### [medium] Spawning processes

Finding ID: `NPS-56E21AFF070A`

File: `index.js:25`

The module directly uses child_process.spawnSync to execute commands synchronously. This is consistent with the package's purpose but still represents a process execution capability.

### [low] Filesystem manipulation (process.chdir)

Finding ID: `NPS-1CD7E3F777DD`

File: `lib/util/resolveCommand.js:15`

The function temporarily changes the process working directory (process.chdir) to the user-supplied parsed.options.cwd before calling which.sync, then restores it. While this is intended to make which operate relative to a custom cwd, it is a global process-wide side effect that can affect other concurrent operations (e.g. other modules reading files by relative path) during that window, and relies on cwd being restorable. This is a legitimate technique used by cross-spawn but is a potential attack surface if parsed.options.cwd is attacker-controlled.

### [low] Path resolution based on unvalidated input

Finding ID: `NPS-EC9D0BEB4D04`

File: `lib/util/resolveCommand.js:26`

resolved is computed by which.sync using env[getPathKey({env})] as PATH and then path.resolve(hasCustomCwd ? parsed.options.cwd : '', resolved). If parsed.options or parsed.command are attacker-controlled, this can resolve to arbitrary paths outside the intended package scope. However, the function itself does not execute anything, it only resolves a path string.

## Files reviewed

- `index.js` (medium): The code is the legitimate cross-spawn package implementation that wraps child_process to provide cross-platform compatibility; it spawns processes by design, with no evidence of exfiltration, obfuscation, or other malicious behavior.
- `lib/util/resolveCommand.js` (medium): No malicious patterns detected; the code performs legitimate command path resolution with twp low-severity concerns around process-wide chdir and path resolution from caller-supplied cwd.
- `lib/enoent.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/parse.js` (safe): This is a legitimate command parsing utility (similar to cross-spawn) that handles shell escaping and shebang detection without any malicious patterns.
- `lib/util/escape.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/util/readShebang.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
