CVE-2025-8022: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in bun
All versions of the package bun are vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the $ shell API due to improper neutralization of user input. An attacker can exploit this by providing specially crafted input that includes command-line arguments or shell metacharacters, leading to unintended command execution.
CVE-2025-8022: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in bun
Description
All versions of the package bun are vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the $ shell API due to improper neutralization of user input. An attacker can exploit this by providing specially crafted input that includes command-line arguments or shell metacharacters, leading to unintended command execution.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- snyk
- Date Reserved
- 2025-07-22T07:57:04.973Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68806cf5ad5a09ad0007c8ef
Added to database: 7/23/2025, 5:02:45 AM
Last updated: 7/23/2025, 5:02:45 AM
Views: 1
Related Threats
CVE-2025-8021: Directory Traversal in files-bucket-server
HighCVE-2025-8020: Server-Side Request Forgery (SSRF) in private-ip
HighCVE-2025-24928: CWE-121 Stack-based Buffer Overflow in xmlsoft libxml2
HighCVE-2025-42947: CWE-94: Improper Control of Generation of Code in SAP_SE SAP FICA ODN framework
MediumCVE-2025-7722: CWE-272 Least Privilege Violation in steverio Social Streams
HighActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.