CVE-2024-3566: Haskell Process Library

Critical severity, CVSS 9.8. EPSS: 6.9% chance of exploitation in the next 30 days.

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

Affected products

  • Haskell Process Library: before 1.6.19.0 (fixed in 1.6.19.0)
  • Node.js Node.js: before 18.20.2 (fixed in 18.20.2); from 19.0.0, before 20.12.2 (fixed in 20.12.2); from 21.0.0, before 21.7.3 (fixed in 21.7.3)
  • PHP PHP: before 8.1.28 (fixed in 8.1.28); from 8.2.0, before 8.2.18 (fixed in 8.2.18); from 8.3.0, before 8.3.6 (fixed in 8.3.6)
  • Rust-Lang Rust: before 1.77.2 (fixed in 1.77.2)
  • Yt-Dlp Project Yt-Dlp: from 2021.04.11, before 2024.04.09 (fixed in 2024.04.09)

Published 2024-04-10. Last modified 2026-06-17.