Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-57283

Опубликовано: 28 янв. 2026
Источник: redhat
CVSS3: 7.8

Описание

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.

A flaw was found in browserstack-local. Improper input sanitization of the logfile variable allows an attacker to inject arbitrary OS commands that are executed when this variable is processed, resulting in arbitrary command execution.

Отчет

To exploit this flaw, an attacker needs to have the ability to set the logfile variable, which typically implies prior access to the configuration files or the environment where the configuration is defined and permission to modify it. Due to this reason, this issue has been rated with an important severity.

Меры по смягчению последствий

To mitigate this issue, implement strict input validation of the logfile variable using an allow-list approach. Ensure the input allows only alphanumeric characters, dots, dashes, underscores, and forward slashes. Any input containing other characters should be rejected immediately.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7io.syndesis-syndesis-parentAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2433928browserstack-local: OS command injection in the logfile variable in lib/Local.js

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
2 месяца назад

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.

github
2 месяца назад

BrowserStack Local vulnerable to Command Injection through logfile variable

CVSS3: 7.8
fstec
7 месяцев назад

Уязвимость параметра logfile библиотеки lib/Local.js npm-пакета browserstack-local программной платформы Node.js, позволяющая нарушителю выполнить произвольную команду

7.8 High

CVSS3