You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Node.js CLI开发:如何安全处理child_process.exec的用户输入?

How to Secure User Input for child_process.exec in Your Node.js CLI

Great question! When passing user input (like process.argv[2]) to child_process.exec, the critical risk you’re facing is shell command injection. Since exec executes your command string through a system shell, special characters in the input (like ;, |, $, or backticks) can be parsed as shell syntax—allowing an attacker to run arbitrary, potentially destructive commands on the host system.

Let’s break down the best ways to secure this scenario:

The safest approach is to avoid exec entirely when dealing with untrusted input. Both execFile and spawn execute the command directly without a shell, accepting arguments as an array. This means user input is treated strictly as a single argument, never parsed as shell code.

Here’s how to rewrite your example with execFile:

const { execFile } = require('child_process');

// Pass arguments as an array—no risky string concatenation needed!
execFile('npm', ['view', '--json', process.argv[2]], (error, stdout, stderr) => {
  if (error) {
    console.error(`Error: ${error.message}`);
    return;
  }
  // Process the JSON output
  const packageInfo = JSON.parse(stdout);
  console.log(packageInfo);
});

This eliminates shell injection risks entirely because the user input is never interpreted as shell syntax.

2. If You Must Use exec: Escape the Input

If you have a specific reason to rely on shell features (like pipes or globbing, which aren’t needed for your npm view use case), you must properly escape the user input to neutralize special characters.

Never try to write your own escape logic—it’s easy to miss edge cases. Instead, use a trusted library like shell-escape (install via npm install shell-escape):

const { exec } = require('child_process');
const shellEscape = require('shell-escape');

// Escape the user input to make it shell-safe
const safePackageName = shellEscape([process.argv[2]]);
const CURL_CHILD = exec(`npm view --json ${safePackageName}`, (error, stdout, stderr) => {
  // Handle results
});

This converts dangerous characters into their shell-safe equivalents, preventing injection attacks.

3. Add Input Validation as an Extra Layer

Even with safe execution methods, validating the input format adds another security barrier. npm package names have strict rules—they can only contain lowercase letters, numbers, and certain symbols (@, /, -, ., _). Reject any input that doesn’t match this pattern:

const packageName = process.argv[2];
const validPackageNameRegex = /^@?[a-z0-9-._]+(\/[a-z0-9-._]+)?$/i;

if (!validPackageNameRegex.test(packageName)) {
  console.error("Error: Invalid package name format");
  process.exit(1);
}

// Proceed with execFile or escaped exec

This ensures only valid npm package names are passed to the command, reducing the attack surface further.

4. Run with Minimal Permissions

Finally, ensure your CLI runs with the least privileges necessary. If an attacker does find a way to inject commands, limiting permissions prevents them from making system-wide changes (like deleting critical files).

内容的提问来源于stack exchange,提问作者Kraken

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:22:47