Ch. 6 · Node.js

Node.js Child Processes and Argument Safety

Node.js Child Processes and Argument Safety. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readintermediateupdated Oct 3, 2026

Launching a process and invoking a shell are different operations. Prefer argument arrays when input should be data rather than shell syntax.

Before you start

You should know JavaScript promises, asynchronous errors and the distinction between a process and a request. When following a server example, identify the resource owner and the point where work completes. Try experiments locally with bounded input instead of assuming production traffic behaves like a single request.

The practical goal is to reason through this situation: Spawn a known executable with separate arguments instead of concatenating a command string. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Fix the executable

Choose a known program rather than accepting an executable name from uncontrolled input.

Step 2: Pass arguments as data

Use argument arrays without shell interpolation. Validate paths and consider the target program’s own option syntax.

Step 3: Bound the process

Limit input, duration, output and working-directory access. Shell avoidance alone does not authorize arbitrary files.

Worked scenario

Spawn a known executable with separate arguments instead of concatenating a command string.

import { spawn } from 'node:child_process';
const child = spawn('node', ['--version'], { shell: false });
child.stdout.on('data', chunk => process.stdout.write(chunk));
child.on('error', error => console.error(error.message));
JavaScript

This harmless example separates executable and arguments. A filename beginning with an option prefix can still matter to the target program, so its argument contract must also be understood.

Common mistake

Shell interpolation can turn user input into executable instructions.

Verify the behavior

Try spaces and shell metacharacters as data in a disposable experiment. Verify argument boundaries and target-program option handling.

Interview exercise

Process an uploaded filename safely.

Answer and reasoning

Validate the path, pass it as an argument and restrict the executable and working directory.

Continue learning

Compare the scenario with the Node.js interview questions and test your understanding with the Node.js MCQs. For terminology and implementation details, consult the reference material.

More in Node.js

read ✓Node.js · hard

Node.js Clustering Across CPU Cores

Use cluster to run several workers on all cores, restart crashed workers, and understand shared-port and shared-state limits.

~2 min readread →
read ✓Node.js · hard

Node.js Password Hashing with scrypt

Store passwords as salted hashes with a slow key-derivation function, and compare candidates in constant time.

~2 min readread →
esc