Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dremig

#26125of 53,624
9.8Total CVSS
Vulnerabilities · 1
PT-2025-36489
9.8
2025-09-08
Unknown · Codeceptjs · CVE-2025-57285
Name of the Vulnerable Software and Affected Versions: codeceptjs version 3.7.3 Description: codeceptjs version 3.7.3 contains a command injection issue in the `emptyFolder` function located in `lib/utils.js`. The `execSync` command directly concatenates the user-controlled `directoryPath` parameter without sanitization or escaping, potentially allowing attackers to execute arbitrary commands. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.