High severity7.8NVD Advisory· Published Jan 28, 2026· Updated Jul 15, 2026
CVE-2025-57283
CVE-2025-57283
Description
The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
browserstack-localnpm | < 1.5.9 | 1.5.9 |
Affected products
2- cpe:2.3:a:browserstack:browserstack-local:1.5.8:*:*:*:*:node.js:*:*
Patches
Vulnerability mechanics
References
8- gist.github.com/Dremig/b639c61541dd1482007dc7a5cd7fefb1nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-g4w6-c99w-4wh7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-57283ghsaADVISORY
- github.com/browserstack/browserstack-local-nodejs/issues/168ghsaWEB
- www.npmjs.comnvdProductWEB
- access.redhat.com/security/cve/CVE-2025-57283nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-57283.jsonnvd
News mentions
0No linked articles in our index yet.