Логотип exploitDog
bind:CVE-2025-66219
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66219

Количество 2

Количество 2

nvd логотип

CVE-2025-66219

2 месяца назад

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether provided to the command-line flag, or is in user control in the target repository. At time of publication, no known fix is public.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-j9wj-m24m-7jj6

2 месяца назад

willitmerge has a Command Injection vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66219

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether provided to the command-line flag, or is in user control in the target repository. At time of publication, no known fix is public.

CVSS3: 9.8
0%
Низкий
2 месяца назад
github логотип
GHSA-j9wj-m24m-7jj6

willitmerge has a Command Injection vulnerability

0%
Низкий
2 месяца назад

Уязвимостей на страницу