# execa@9.6.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:15.000Z
- Files reviewed: 106
- Findings: 2 medium, 5 low severity findings
- Report: https://security.togoder.click/npm/execa@9.6.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package execa@9.6.1 on Oct 6, 2026. An AI review of 106 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Shell command concatenation without escaping

Finding ID: `NPS-AEA9C3571874`

File: `lib/arguments/shell.js:9`

The `concatenateShell` function joins `file` and its arguments with spaces into a single shell command string when `options.shell` is enabled. This replicates Node.js's internal shell concatenation but performs no quoting, escaping, or validation. If any argument originates from untrusted input, it can be interpreted by the shell (command injection, argument injection, or option injection). While the code itself does not exfiltrate data or spawn processes directly, it deliberately constructs shell-parsed command strings, which is a dangerous pattern when callers pass user-controlled values.

### [medium] Template string parsing (potential shell injection surface)

Finding ID: `NPS-D56B64ED43E1`

File: `lib/methods/template.js:8`

This module parses execa tagged template literals into a file + argument array. Since it splits only on whitespace and performs no shell quoting, the actual safety of command invocation depends on the caller passing the resulting array to a non-shell exec API (e.g., spawn/execFile). If a downstream consumer ever joins these arguments through a shell, user-controlled template expressions could be interpreted as shell syntax.

### [low] Environment variable access

Finding ID: `NPS-BB96B6DCAF76`

File: `lib/methods/main-async.js`

While the code passes options to spawn, there is no evidence of harvesting credentials or environment variables for exfiltration. The options are user-provided and used for normal subprocess execution.

### [low] Spawning processes

Finding ID: `NPS-3E66609AB20E`

File: `lib/methods/main-async.js:57`

The code uses child_process.spawn to execute external commands, which is expected behavior for the 'execa' package that provides subprocess execution. The spawned commands come from the arguments passed to the library, not from hardcoded malicious inputs.

### [low] Spawning processes

Finding ID: `NPS-A6D65B7380F6`

File: `lib/methods/main-sync.js:1`

The code imports and uses child_process.spawnSync to execute subprocesses. This is expected and legitimate behavior for the execa library, which is designed as a process execution wrapper. No suspicious arguments or data exfiltration are present; spawn is called with parameters derived from caller-supplied options.

### [low] Child process reference (not instantiation)

Finding ID: `NPS-CC4A3E6A4B89`

File: `lib/methods/template.js:1`

The file imports ChildProcess from node:child_process, but only uses it for an instanceof check to throw a helpful error when a subprocess is interpolated into a template expression. No process is spawned in this file.

### [low] Process termination on exit

Finding ID: `NPS-0476CD13A77E`

File: `lib/terminate/cleanup.js:9`

The code registers an onExit handler that calls subprocess.kill() to terminate a child process when the parent process exits. While this is a legitimate cleanup pattern, it involves killing a process, which could be abused if the subprocess reference is controlled or if the cleanup option is enabled unexpectedly. However, the code only runs if the 'cleanup' option is true and the process is not detached, and it is a common pattern in process management libraries.

## Files reviewed

- `lib/arguments/shell.js` (medium): The code safely normalizes shell argument handling but performs unescaped string concatenation for shell execution, creating a potential command-injection risk depending on caller-supplied arguments.
- `lib/terminate/cleanup.js` (medium): The code implements a cleanup-on-exit handler to kill a subprocess, which is a benign pattern but involves process termination and could be misused in edge cases.
- `index.js` (safe): No malicious patterns detected; the file is a standard entry point that re-exports the execa library's public API.
- `lib/arguments/command.js` (safe): No malicious patterns detected
- `lib/arguments/cwd.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/arguments/encoding-option.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/arguments/escape.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/arguments/fd-options.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/arguments/file-url.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/arguments/options.js` (safe): No malicious patterns detected
- `lib/arguments/specific.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/convert/add.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/convert/concurrent.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/convert/duplex.js` (safe): No malicious patterns detected; the code creates a Duplex stream wrapper around a subprocess without any network, filesystem, or code execution concerns.
- `lib/convert/iterable.js` (safe): No malicious patterns detected; the code is a straightforward async iterable converter for subprocess stdout streams.
- `lib/convert/readable.js` (safe): No malicious patterns detected; code implements a readable stream wrapper for subprocess stdout with no exfiltration, obfuscation, credential access, or network activity.
- `lib/convert/shared.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/convert/writable.js` (safe): No malicious patterns detected in this stream-wrapping utility module.
- `lib/io/contents.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/input-sync.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/iterate.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/max-buffer.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/output-async.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/output-sync.js` (safe): The code performs synchronous output transformation and file writing for stdout/stderr handling without any malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning.
- `lib/io/pipeline.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/io/strip-newline.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/ipc/array.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/ipc/buffer-messages.js` (safe): The code safely iterates and buffers IPC messages from a subprocess without any malicious patterns such as exfiltration, credential harvesting, or dynamic code execution.
- `lib/ipc/forward.js` (safe): No malicious patterns detected
- `lib/ipc/get-each.js` (safe): No malicious patterns detected
- `lib/ipc/get-one.js` (safe): No malicious patterns detected; the code is a legitimate IPC message-handling utility for subprocess communication.
- `lib/ipc/graceful.js` (safe): The code implements IPC-based graceful cancellation for subprocesses using standard Node.js APIs with no malicious patterns detected.
- `lib/ipc/incoming.js` (safe): No malicious patterns detected
- `lib/ipc/ipc-input.js` (safe): No malicious patterns detected; the code only validates and forwards an IPC input option using standard serialization checks.
- `lib/ipc/methods.js` (safe): No malicious patterns detected; the code implements standard Node.js IPC helper methods without exfiltration, credential harvesting, obfuscation, or other red flags.
- `lib/ipc/outgoing.js` (safe): No malicious patterns detected; the code implements internal IPC message synchronization for a subprocess library without network, filesystem, credential, or dynamic execution concerns.
- `lib/ipc/reference.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/ipc/send.js` (safe): No malicious patterns detected; the code implements a promise-based IPC send utility with validation, strict response handling, and error management, without any data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
- `lib/ipc/strict.js` (safe): No malicious patterns detected
- `lib/ipc/validation.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/methods/bind.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/methods/command.js` (safe): No malicious patterns detected
- `lib/methods/create.js` (safe): No malicious patterns detected; the code is a legitimate argument parsing and execution wrapper for the execa library.
- `lib/methods/main-async.js` (safe): The code is part of the legitimate 'execa' npm package and contains standard subprocess execution logic without any malicious patterns.
- `lib/methods/main-sync.js` (safe): No malicious patterns detected; child_process usage is the intended core functionality of the execa package.
- `lib/methods/node.js` (safe): No malicious patterns detected; the code is a legitimate utility module for the execa package that handles Node.js execution options without any exfiltration, credential harvesting, or obfuscation.
- `lib/methods/parameters.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/methods/promise.js` (safe): No malicious patterns detected; code only mixes Promise methods into a subprocess object using standard reflection.
- `lib/methods/script.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/methods/template.js` (safe): The file only parses execa tagged template strings into command/argument arrays and performs type checks; no exfiltration, credential harvesting, dynamic evaluation, process spawning, or filesystem manipulation is present, though callers must ensure the resulting argument array is never passed through a shell.
- `lib/pipe/abort.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/pipe/pipe-arguments.js` (safe): No malicious patterns detected; the code appears to be legitimate argument normalization for the execa npm package.
- `lib/pipe/sequence.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/pipe/setup.js` (safe): The code is part of a subprocess piping library and contains no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
- `lib/pipe/streaming.js` (safe): No malicious patterns detected; the code implements standard stream piping with merge-streams and listener management, with no data exfiltration, credential harvesting, obfuscation, network calls, or subprocess spawning.
- `lib/pipe/throw.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/all-async.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/all-sync.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/exit-async.js` (safe): No malicious patterns detected; the code is a legitimate subprocess exit-waiting utility using standard Node.js event handling.
- `lib/resolve/exit-sync.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/stdio.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/wait-stream.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/resolve/wait-subprocess.js` (safe): This file is part of a subprocess management utility (resembling execa) and contains no malicious patterns; it handles process lifecycle, stream waiting, timeouts, and IPC without exfiltration, credential harvesting, obfuscation, or other red flags.
- `lib/return/duration.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/return/early-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/return/final-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/return/message.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/return/reject.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/return/result.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stdio/direction.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stdio/duplicate.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stdio/handle-async.js` (safe): The code is a standard stream handling utility with no malicious patterns, network calls, or suspicious behavior.
- `lib/stdio/handle-sync.js` (safe): No malicious patterns detected; the code synchronously handles stdio options for process spawning with no exfiltration, obfuscation, or unauthorized file/network/process operations.
- `lib/stdio/handle.js` (safe): No malicious patterns detected; the code is a legitimate stdio option handling module from the Execa library with no exfiltration, credential harvesting, obfuscation, or command execution.
- `lib/stdio/input-option.js` (safe): No malicious patterns detected; this is a benign input validation and normalization module for stdio options.
- `lib/stdio/native.js` (safe): No malicious patterns detected
- `lib/stdio/stdio-option.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stdio/type.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/terminate/cancel.js` (safe): No malicious patterns detected
- `lib/terminate/graceful.js` (safe): This file implements graceful subprocess termination logic using AbortSignal and IPC, with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or suspicious network/file/process operations.
- `lib/terminate/kill.js` (safe): No malicious patterns detected
- `lib/terminate/signal.js` (safe): No malicious patterns detected; the code only normalizes and validates OS signals using Node.js built-ins and human-signals.
- `lib/terminate/timeout.js` (safe): No malicious patterns detected; the code is a legitimate timeout utility for subprocess termination.
- `lib/transform/encoding-transform.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/generator.js` (safe): No malicious patterns detected
- `lib/transform/normalize.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/object-mode.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/run-async.js` (safe): No malicious patterns detected; the code only implements asynchronous transform utilities using Node.js util.callbackify and async generators without any network, filesystem, process, or dynamic execution concerns.
- `lib/transform/run-sync.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/split.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/transform/validate.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils/abort-signal.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils/deferred.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils/max-listeners.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils/standard-stream.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils/uint-array.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/complete.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/custom.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/default.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/error.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/info.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/ipc.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/log.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/output.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/start.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/verbose/values.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 3 scanned versions of execa are flagged high or critical. The latest scanned version, 10.0.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.0.1 – 10.0.1 (`>=8.0.1 <=10.0.1`): medium (Shell command concatenation without escaping +4 more)
- 0.7.0 – 7.2.0 (`>=0.7.0 <=7.2.0`): not scanned

## Scanned versions

- [10.0.1](https://security.togoder.click/npm/execa@10.0.1): medium, 2026-10-06T14:16:34.000Z
- [9.6.1](https://security.togoder.click/npm/execa@9.6.1): medium, 2026-10-06T14:12:15.000Z
- [8.0.1](https://security.togoder.click/npm/execa@8.0.1): medium, 2026-10-06T14:15:59.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
