GHSA-4j66-8f4r-3pjx

Suggest an improvement
Source
https://github.com/advisories/GHSA-4j66-8f4r-3pjx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-4j66-8f4r-3pjx/GHSA-4j66-8f4r-3pjx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4j66-8f4r-3pjx
Aliases
  • CVE-2025-8022
Published
2025-07-23T06:33:50Z
Modified
2025-07-23T17:42:18Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
  • 7.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
bun vulnerable to OS Command Injection
Details

All versions of the package bun are vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the $ shell API due to improper neutralization of user input. An attacker can exploit this by providing specially crafted input that includes command-line arguments or shell metacharacters, leading to unintended command execution.

Database specific
{
    "cwe_ids":  [
        "CWE-78"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-07-23T16:38:39Z",
    "nvd_published_at":  "2025-07-23T05:15:30Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / bun

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.1.39

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-4j66-8f4r-3pjx/GHSA-4j66-8f4r-3pjx.json"