CNNVD-202511-3048 Information

CNNVD ID

CNNVD-202511-3048

CVE-2025-66219

  • CNNVD Published: 2025-11-29

Description (Chinese)

willitmerge是Kyle Robinson Young个人开发者的一个命令行工具。 willitmerge 0.2.1及之前版本存在命令注入漏洞,该漏洞源于不安全子进程执行API使用不当,可能导致命令注入。

Description (English)

Willitmerge is a command line tool for Kyle Robinson Young’s personal developer. There is a gap in commands in the willitmerge 0.2.1 and earlier versions, which stems from the improper use of API by unsafe sub-processes, which may lead to the injection of orders.

Hazard Level

High

Vulnerability Type

命令注入

Affected Vendor

个人开发者

Published

2025-11-29

Last Modified

2026-02-24

References

https://github.com/shama/willitmerge/blob/2fe91d05191fb05ac6da685828d109a3a5885028/lib/willitmerge.js#L189-L197 https://github.com/shama/willitmerge/security/advisories/GHSA-j9wj-m24m-7jj6 https://access.redhat.com/security/cve/cve-2025-66219

Share on: