CVE Details
Basic Information
| Title | CVE-2025-8022 |
|---|---|
| Type | cve |
| Published | 2025-07-23T05:00:06.702Z |
| Modified | 2025-07-23T05:00:06.702Z |
Product Information
| Vendor | n/a |
|---|---|
| Product | bun |
| Version | 0 |
CVSS Information
| Base Score | 8.8 (HIGH) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P |
Affected Products
- n/a bun 0
Additional Information
| Source | snyk |
|---|
Description
All versions of the package bun are vulnerable to Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) in the $ shell API due to improper neutralization of user input. An attacker can exploit this by providing specially crafted input that includes command-line arguments or shell metacharacters, leading to unintended command execution.