PT-2025-39662 · Sonarsource · Sonarqube

Published

2025-09-26

·

Updated

2025-10-08

·

CVE-2025-59844

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SonarQube versions prior to 6.0.0
Description A command injection issue exists in the SonarQube GitHub Action when workflows pass user-controlled input to the args parameter on Windows runners without proper validation. This bypasses a previous security fix and allows arbitrary command execution, potentially leading to exposure of sensitive environment variables and compromise of the runner environment.
Recommendations Upgrade to version 6.0.0 or later.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-59844
GHSA-5XQ9-5G24-4G6F

Affected Products

Sonarqube