PT-2025-39958 · Unknown · Check-Branches

Liran Tal

·

Published

2025-09-30

·

Updated

2025-10-05

·

CVE-2025-11148

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions check-branches (affected versions not specified)
Description The software is susceptible to a command injection issue. The tool trusts branch names without sanitization and constructs git commands by concatenating user input. This allows attackers to execute arbitrary commands through maliciously crafted branch names, potentially gained through pull requests or privileged repository access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-11148
GHSA-9C4G-FP4R-PRRV

Affected Products

Check-Branches