Skip to main content

CVE-2025-8022: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in bun

High
VulnerabilityCVE-2025-8022cvecve-2025-8022
Published: Wed Jul 23 2025 (07/23/2025, 05:00:06 UTC)
Source: CVE Database V5
Product: bun

Description

All versions of the package bun are vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the $ shell API due to improper neutralization of user input. An attacker can exploit this by providing specially crafted input that includes command-line arguments or shell metacharacters, leading to unintended command execution.

Technical Details

Data Version
5.1
Assigner Short Name
snyk
Date Reserved
2025-07-22T07:57:04.973Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 68806cf5ad5a09ad0007c8ef

Added to database: 7/23/2025, 5:02:45 AM

Last updated: 7/23/2025, 5:02:45 AM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats