CodeZettaInterview Hub

Node.js · Security · Mid-Level · Best Practice

child_process with user input — safe patterns?

Short Interview Answer

Avoid shell; use execFile/spawn with arg arrays; allowlist commands; never concatenate untrusted strings into shells.

Detailed Explanation

Shell injection is still common. Prefer no user-controlled commands at all.

Common Mistake

exec(`ls ${userDir}`) with shell:true.

Did you know this answer?