Node.js · Security · Mid-Level · Best Practice
child_process with user input — safe patterns?
Short Interview Answer
Avoid shell; use execFile/spawn with arg arrays; allowlist commands; never concatenate untrusted strings into shells.
Detailed Explanation
Shell injection is still common. Prefer no user-controlled commands at all.
Common Mistake
exec(`ls ${userDir}`) with shell:true.