A AegiFlow
CRITICALCVSS 9.8

CVE-2024-3566

CVE-2024-3566 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

Affected packages

EcosystemPackageAffected versionsFixed versions
Node.jsnode.js[object Object], [object Object], [object Object]
PHPphp[object Object], [object Object], [object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.