PT-2025-30525 · Bun · Bun

Liran Tal

·

Published

2025-07-23

·

Updated

2025-08-14

·

CVE-2025-8022

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bun (affected versions not specified)
Description The package is susceptible to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') within the shell API. This occurs due to insufficient neutralization of user-supplied input. An attacker can leverage this by providing specially crafted input containing command-line arguments or shell metacharacters, potentially resulting in unintended command execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-8022
GHSA-4J66-8F4R-3PJX

Affected Products

Bun