PT-2025-48356 · Unknown · Willitmerge

Lirantal

·

Published

2025-11-29

·

Updated

2025-12-19

·

CVE-2025-66219

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions willitmerge versions 0.2.1 and prior
Description willitmerge is a command line tool used to check if pull requests are mergeable. A command injection issue exists because the software uses an insecure child process execution API (exec) and concatenates user-supplied data to it. User input, whether provided through command-line flags or controlled within the target repository, is not properly sanitized before being used in the exec function. This allows for potential arbitrary command execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-66219
GHSA-J9WJ-M24M-7JJ6

Affected Products

Willitmerge