codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Mon, 08 Sep 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-08T19:40:26.439Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57285

Updated: 2025-09-08T19:40:14.852Z

Status : Received
Published: 2025-09-08T18:15:34.160
Modified: 2025-09-08T20:15:35.837
Link: CVE-2025-57285

No data.

No data.