CVE Feed

    Dashboard / CVE / CVE-2025-66219

    CVE-2025-66219

    willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether provided to the command-line flag, or is in user control in the target repository. At time of publication, no known fix is public.

    Published:Nov 29, 2025
    Last Modified:Dec 19, 2025
    EPS:Nov 29, 2025
    EPSS Score:0.01114
    CVSS Score:9.8

    Affected Products

    Vendor
    Dontkry
    Product
    Willitmerge
    Vendor
    Willitmerge Project
    Product
    Willitmerge

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High