GHSA-5j98-mcp5-4vw2 · Severity: high · Ecosystem: npm — glob CLI: Command injection via -c/--cmd executes matches with shell:true
Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command injection vulnerability in its -c/--cmd option that allows arbitrary command execution when processing files with malicious names. When glob -c <command> <patterns> are used, matched filenames are passed to a shell with shell: true, enabling shell metacharacters in filenames to trigger command injection and achieve arbitrary code execution under the user or CI account privileges. This issue has been patched in versions 10.5.0 and 11.1.0.
Conclusion & alert: CVE-2025-64756 is rated Exploit Available (50/100): CVSS High severity, with low exploitation likelihood (EPSS 0.04%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-12-03 | 0.06% | 0.04% | -0.02% |
| 2 | 2025-11-23 | 0.04% | 0.06% | +0.01% |
| 3 | 2025-11-21 | — | 0.04% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
1.6 | 5.9 | [email protected] |
GHSA-5j98-mcp5-4vw2 · Severity: high · Ecosystem: npm — glob CLI: Command injection via -c/--cmd executes matches with shell:true
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-64756: 1 source package rows (npm); 12 state rows across 2 repos (3.22-community, edge-community); fixed 1, open 11. | https://security.alpinelinux.org/vuln/CVE-2025-64756 |
debian
|
unimportant | CVE-2025-64756 unimportant priority: Debian including 1 source packages (node-glob), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2025-64756 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-64756 |
ubuntu
|
medium | CVE-2025-64756 medium priority: Ubuntu including 1 source packages (node-glob), 9 status rows across 9 suites (bionic, focal, jammy, noble, plucky, questing, trusty, upstream, xenial): not-affected 9. | https://ubuntu.com/security/CVE-2025-64756 |