Home

Description

codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands.

PUBLISHED Reserved 2025-08-17 | Published 2025-09-08 | Updated 2025-09-08 | Assigner mitre

References

www.npmjs.com

gist.github.com/Dremig/1ba111f9b1f7cffe1fcb4838b64e55b9

cve.org (CVE-2025-57285)

nvd.nist.gov (CVE-2025-57285)

Download JSON