CVE-2025-64756
HIGHThe glob CLI contains a command injection vulnerability in its -c/--cmd option that allows arbitrary command execution when processing files with malicious names. When glob -c <command> <patterns> is used, matched filenames are passed to a shell with shell: true, enabling shell metacharacters in filenames to trigger command injection and achieve arbitrary code execution under the user or CI accoun
- Affected
- >=11.0.0, <11.1.0
- Fixed in
- not stated
- Weakness
- CWE-78
- Published
- 2025-11-17
- Source
- NVD