# execa@10.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:34.000Z
- Files reviewed: 109
- Findings: 2 medium, 7 low severity findings
- Report: https://security.togoder.click/npm/execa@10.0.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package execa@10.0.1 on Oct 6, 2026. An AI review of 109 source files produced 2 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Spawning processes or shell commands

Finding ID: `NPS-5E4A35DD28C8`

File: `lib/arguments/command-file.js`

The code constructs and executes Windows command lines via cmd.exe with 'windowsVerbatimArguments' enabled and manual escaping logic. While the escaping appears intentional and defensive (rejecting CR/LF, caret-escaping metacharacters), this pattern is inherently high-risk and could enable command injection if any escaping edge case is missed or if an attacker can influence the file path or arguments.

### [medium] Shell command concatenation without escaping

Finding ID: `NPS-AEA9C3571874`

File: `lib/arguments/shell.js:9`

The `concatenateShell` function joins `file` and its arguments with spaces into a single shell command string when `options.shell` is enabled. This replicates Node.js's internal shell concatenation but performs no quoting, escaping, or validation. If any argument originates from untrusted input, it can be interpreted by the shell (command injection, argument injection, or option injection). While the code itself does not exfiltrate data or spawn processes directly, it deliberately constructs shell-parsed command strings, which is a dangerous pattern when callers pass user-controlled values.

### [low] File system read outside package scope

Finding ID: `NPS-5F0CFD34FFB0`

File: `lib/arguments/command-file.js`

readShebang opens and reads the first 150 bytes of arbitrary resolved files to parse shebang interpreters. This is expected for command resolution but does involve reading files outside the package boundary.

### [low] Environment variable harvesting

Finding ID: `NPS-616BE54A33D8`

File: `lib/arguments/command-file.js`

The code reads PATH, PATHEXT, comspec, and NODEFAULTCURRENTDIRECTORYINEXEPATH environment variables. These are standard for Windows command resolution and are not credential-related, but environment access is present.

### [low] Dynamic path resolution using external inputs

Finding ID: `NPS-D2EBF067A10D`

File: `lib/arguments/command-file.js`

whichCommandSync is used with user-supplied file/command names to resolve executables from PATH/PATHEXT. This can cause execution of unexpected binaries if the environment is attacker-controlled, though it is standard behavior for command launchers.

### [low] Process spawning

Finding ID: `NPS-1602732130CC`

File: `lib/methods/main-async.js:90`

Uses child_process.spawn to execute subprocesses, but this is the core purpose of the execa library and arguments are normalized through internal handlers; no unsanitized user input or external dynamic commands are present.

### [low] ChildProcess import

Finding ID: `NPS-05FEAE71C8C2`

File: `lib/methods/template.js:1`

The file imports ChildProcess from 'node:child_process', but only uses it for type checking (instanceof) to validate template expressions, not for executing commands.

### [low] Process Spawning

Finding ID: `NPS-AFAF96020C3B`

File: `lib/terminate/kill-descendants.js:60`

The code uses child_process.execFile to spawn taskkill.exe on Windows for terminating process trees. This is a legitimate use case for process termination and not a malicious pattern. The executable path is derived from environment variables (SystemRoot/windir) and validated to be a Windows drive absolute path before joining with System32\taskkill.exe.

### [low] Environment Variable Usage

Finding ID: `NPS-9986573E60F7`

File: `lib/terminate/kill-descendants.js:74`

Reads SystemRoot and windir environment variables to locate taskkill.exe on Windows. This is standard practice for locating system executables and does not constitute credential harvesting.

## Files reviewed

- `lib/arguments/command-file.js` (medium): The file implements Windows command-line escaping and resolution for a well-known package (execa); it contains no exfiltration, credential theft, obfuscation, or backdoor patterns, but does spawn cmd.exe and read environment/filesystem paths in ways that warrant a warning-level review.
- `lib/arguments/shell.js` (medium): The code safely normalizes shell argument handling but performs unescaped string concatenation for shell execution, creating a potential command-injection risk depending on caller-supplied arguments.
- `index.js` (safe): This is the public entry point for the execa package, containing only standard imports/exports with no malicious patterns, obfuscation, or suspicious behavior.
- `lib/arguments/command.js` (safe): No malicious patterns detected
- `lib/arguments/cwd.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/arguments/encoding-option.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/arguments/escape.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/arguments/fd-options.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/arguments/file-url.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/arguments/options.js` (safe): No malicious patterns detected; the code performs standard option normalization for a child process library with explicit prototype pollution protections.
- `lib/arguments/specific.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/convert/add.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/convert/concurrent.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/convert/duplex.js` (safe): No malicious patterns detected; the code only constructs a Node.js Duplex stream wrapper around a subprocess with no external network, filesystem, or process-spawning behavior.
- `lib/convert/iterable.js` (safe): No malicious patterns detected; the code is a straightforward async iterable converter for subprocess stdout streams.
- `lib/convert/readable.js` (safe): No malicious patterns detected
- `lib/convert/shared.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/convert/web.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/convert/writable.js` (safe): No malicious patterns detected in the writable stream conversion module; it only handles subprocess I/O forwarding without any suspicious behavior.
- `lib/io/contents.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/input-sync.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/iterate.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/max-buffer.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/output-async.js` (safe): No malicious patterns detected; the module only handles stream piping for subprocess I/O with no external network, credential, or code execution activities.
- `lib/io/output-sync.js` (safe): No malicious patterns detected; the code performs synchronous output handling with file writes only to user-specified paths, and contains no exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/io/pipeline.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/strip-newline.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/ipc/array.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/ipc/buffer-messages.js` (safe): The code safely iterates and buffers IPC messages from a subprocess without any malicious patterns such as exfiltration, credential harvesting, or dynamic code execution.
- `lib/ipc/forward.js` (safe): No malicious patterns detected; the code only forwards IPC events between processes using standard Node.js APIs.
- `lib/ipc/get-each.js` (safe): No malicious patterns detected
- `lib/ipc/get-one.js` (safe): No malicious patterns detected; the code is a standard IPC message handler with no exfiltration, obfuscation, or unsafe operations.
- `lib/ipc/graceful.js` (safe): No malicious patterns detected; the file implements legitimate Inter-Process Communication (IPC) cancellation handling for the execa library with no exfiltration, credential harvesting, obfuscation, or shell execution.
- `lib/ipc/incoming.js` (safe): No malicious patterns detected
- `lib/ipc/ipc-input.js` (safe): The code is a straightforward IPC input validation and sending utility with no malicious patterns; it only serializes and sends user-provided input to a subprocess channel.
- `lib/ipc/methods.js` (safe): No malicious patterns detected; the code only implements standard Node.js process IPC wrappers without any exfiltration, obfuscation, or suspicious behavior.
- `lib/ipc/outgoing.js` (safe): No malicious patterns detected
- `lib/ipc/reference.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/ipc/send.js` (safe): No malicious patterns detected; the code implements a promise-based IPC send utility with validation, strict response handling, and error management, without any data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
- `lib/ipc/strict.js` (safe): No malicious patterns detected
- `lib/ipc/validation.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/methods/bind.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/methods/command.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/methods/create.js` (safe): No malicious patterns detected; the code is a legitimate argument-parsing and method-wrapping module for the execa package.
- `lib/methods/main-async.js` (safe): No malicious patterns detected; child_process usage is expected for this subprocess execution library and no exfiltration, credential harvesting, obfuscation, or backdoor behavior was found.
- `lib/methods/main-sync.js` (safe): No malicious patterns detected
- `lib/methods/node.js` (safe): No malicious patterns detected
- `lib/methods/parameters.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/methods/promise.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/methods/script.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/methods/template.js` (safe): This code safely parses tagged template strings for the execa library without any malicious patterns such as data exfiltration, environment harvesting, obfuscated code, or unauthorized process execution.
- `lib/pipe/abort.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/pipe/pipe-arguments.js` (safe): No malicious patterns detected; the code appears to be legitimate argument normalization for the execa npm package.
- `lib/pipe/sequence.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/pipe/setup.js` (safe): No malicious patterns detected
- `lib/pipe/streaming.js` (safe): No malicious patterns detected; the code implements standard stream piping with merge-streams and listener management, with no data exfiltration, credential harvesting, obfuscation, network calls, or subprocess spawning.
- `lib/pipe/throw.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/all-async.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/all-sync.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/exit-async.js` (safe): No malicious patterns detected; the code is a legitimate subprocess exit-waiting utility using standard Node.js event handling.
- `lib/resolve/exit-sync.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/stdio.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/wait-stream.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/wait-subprocess.js` (safe): No malicious patterns detected; the code is a legitimate subprocess result handler with no exfiltration, credential harvesting, obfuscation, or suspicious process/network operations.
- `lib/return/duration.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/return/early-error.js` (safe): No malicious patterns detected; the code handles early subprocess spawn errors by creating dummy streams and an error-wrapping promise without any exfiltration, credential harvesting, obfuscation, or shell execution.
- `lib/return/final-error.js` (safe): No malicious patterns detected; the code only defines custom Error classes and a helper to convert subprocess errors, with no network, filesystem, process spawning, or obfuscation behavior.
- `lib/return/message.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/return/reject.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/return/result.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stdio/direction.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stdio/duplicate.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stdio/handle-async.js` (safe): The code is a standard stream handling utility with no malicious patterns, network calls, or suspicious behavior.
- `lib/stdio/handle-sync.js` (safe): No malicious patterns detected
- `lib/stdio/handle.js` (safe): No malicious patterns detected
- `lib/stdio/input-option.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stdio/native.js` (safe): No malicious patterns detected
- `lib/stdio/stdio-option.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stdio/type.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/terminate/cancel.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/terminate/cleanup.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/terminate/graceful.js` (safe): No malicious patterns detected; the file contains legitimate subprocess termination logic with proper validation, error handling, and no network, filesystem, or dynamic code execution risks.
- `lib/terminate/kill-descendants.js` (safe): The code safely implements process tree termination on Unix and Windows using standard OS mechanisms without any malicious patterns.
- `lib/terminate/kill.js` (safe): No malicious patterns detected
- `lib/terminate/signal.js` (safe): No malicious patterns detected; the code only normalizes and validates OS signals using Node.js built-ins and human-signals.
- `lib/terminate/timeout.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/encoding-transform.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/generator.js` (safe): No malicious patterns detected
- `lib/transform/normalize.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/object-mode.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/run-async.js` (safe): No malicious patterns detected; the code only implements asynchronous transform utilities using Node.js util.callbackify and async generators without any network, filesystem, process, or dynamic execution concerns.
- `lib/transform/run-sync.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/split.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/validate.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils/abort-signal.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils/deferred.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils/max-listeners.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils/standard-stream.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils/uint-array.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/complete.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/custom.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/default.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/error.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/info.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/ipc.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/log.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/output.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/start.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/values.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 3 scanned versions of execa are flagged high or critical. The latest scanned version, 10.0.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.0.1 – 10.0.1 (`>=8.0.1 <=10.0.1`): medium (Shell command concatenation without escaping +4 more)
- 0.7.0 – 7.2.0 (`>=0.7.0 <=7.2.0`): not scanned

## Scanned versions

- [10.0.1](https://security.togoder.click/npm/execa@10.0.1): medium, 2026-10-06T14:16:34.000Z
- [9.6.1](https://security.togoder.click/npm/execa@9.6.1): medium, 2026-10-06T14:12:15.000Z
- [8.0.1](https://security.togoder.click/npm/execa@8.0.1): medium, 2026-10-06T14:15:59.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
