Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66219

Опубликовано: 29 нояб. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether provided to the command-line flag, or is in user control in the target repository. At time of publication, no known fix is public.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dontkry:willitmerge:*:*:*:*:*:node.js:*:*
Версия до 0.2.1 (включая)

EPSS

Процентиль: 47%
0.00242
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

github
2 месяца назад

willitmerge has a Command Injection vulnerability

EPSS

Процентиль: 47%
0.00242
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77