PT-2025-48356 · Unknown · Willitmerge
Lirantal
·
Published
2025-11-29
·
Updated
2025-12-19
·
CVE-2025-66219
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
willitmerge versions 0.2.1 and prior
Description
willitmerge is a command line tool used to check if pull requests are mergeable. A command injection issue exists because the software uses an insecure child process execution API (
exec) and concatenates user-supplied data to it. User input, whether provided through command-line flags or controlled within the target repository, is not properly sanitized before being used in the exec function. This allows for potential arbitrary command execution.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Willitmerge