216.73.217.22

CVE-2025-66219

· Published 29/11/2025 02:15 · Modified 19/12/2025 15:52

Labels: CVE-2025-66219 2025-11-29CVE-2025-66219CWE-77[email protected]

Essential information

Published
29/11/2025 02:15
Modified
19/12/2025 15:52
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether provided to the command-line flag, or is in user control in the target repository. At time of publication, no known fix is public.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
dontkry / willitmerge cpe:2.3:a:dontkry:willitmerge:*:*:*:*:*:node.js:*:*

References