Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-57283

Опубликовано: 28 янв. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.

A flaw was found in browserstack-local. Improper input sanitization of the logfile variable allows an attacker to inject arbitrary OS commands that are executed when this variable is processed, resulting in arbitrary command execution.

Отчет

To exploit this flaw, an attacker needs to have the ability to set the logfile variable, which typically implies prior access to the configuration files or the environment where the configuration is defined and permission to modify it. Due to this reason, this issue has been rated with an important severity.

Меры по смягчению последствий

To mitigate this issue, implement strict input validation of the logfile variable using an allow-list approach. Ensure the input allows only alphanumeric characters, dots, dashes, underscores, and forward slashes. Any input containing other characters should be rejected immediately.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7io.syndesis-syndesis-parentWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2433928browserstack-local: OS command injection in the logfile variable in lib/Local.js

EPSS

Процентиль: 50%
0.00705
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
7 месяцев назад

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.

github
7 месяцев назад

BrowserStack Local vulnerable to Command Injection through logfile variable

CVSS3: 7.8
fstec
12 месяцев назад

Уязвимость параметра logfile библиотеки lib/Local.js npm-пакета browserstack-local программной платформы Node.js, позволяющая нарушителю выполнить произвольную команду

EPSS

Процентиль: 50%
0.00705
Низкий

7.8 High

CVSS3