← Back to browse · API

CVE-2025-57285

Severity
CRITICAL
CVSS
9.8
EPSS
0.02169
Risk score
39.96
CISA KEV
No
PoC
No
Published
2025-09-08
Modified
2025-09-08
First seen
2026-08-07
Aliases
EUVD-2025-27152, GHSA-34W8-MCWR-VG29
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-27152

Description

codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands.

References