Critical severity9.8NVD Advisory· Published Sep 8, 2025· Updated Jun 17, 2026
CVE-2025-57285
CVE-2025-57285
Description
codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
codeceptjsnpm | >= 3.5.0, < 3.7.5 | 3.7.5 |
Affected products
3- cpe:2.3:a:codecept:codeceptjs:3.7.3:*:*:*:*:node.js:*:*
Patches
Vulnerability mechanics
References
6- gist.github.com/Dremig/1ba111f9b1f7cffe1fcb4838b64e55b9nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-34w8-mcwr-vg29ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-57285ghsaADVISORY
- github.com/codeceptjs/CodeceptJS/pull/3604ghsaWEB
- github.com/codeceptjs/CodeceptJS/pull/5190ghsaWEB
- www.npmjs.comnvdProductWEB
News mentions
0No linked articles in our index yet.