PT-2025-22412 · Ejson2Env · Ejson2Env

Published

2025-05-21

·

Updated

2025-05-26

·

CVE-2025-48069

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ejson2env versions prior to 2.0.8
Description The issue is related to inadequate output sanitization in the ejson2env tool, which can lead to command injection. This occurs when variable names or values contain malicious content, resulting in unintended commands being output to stdout. If this output is improperly utilized in further command execution, an attacker could execute arbitrary commands on the host system.
Recommendations For versions prior to 2.0.8, update to version 2.0.8, which sanitizes output during decryption. As a temporary workaround, consider avoiding the use of ejson2env to decrypt untrusted user secrets. Restrict evaluating or executing the direct output from ejson2env without removing nonprintable characters.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-48069
GHSA-2C47-M757-32G6
GO-2025-3702
OPENSUSE-SU-2025:15159-1

Affected Products

Ejson2Env