Junglewise Threat Intelligence

CVE-2025-57282: ngrok npm package command injection via binPath option

CVE-2025-57282 · Severity: high · CVSS 8.8 · Published 2026-05-18

Executive brief

The ngrok npm package, which is used to create secure tunnels to local servers, is vulnerable to a security flaw that allows for unauthorized command execution. An attacker who can influence the configuration options of the library could execute arbitrary commands on the underlying system. This could lead to a full system compromise, data theft, or service disruption.

Technical details

The ngrok npm package (specifically versions 4.3.3 and 5.0.0-beta.2) is vulnerable to command injection (CWE-77). The vulnerability exists because the library fails to properly neutralize special characters in the 'binPath' property of the options object passed to functions like getVersion(). An attacker who can control these options can inject shell commands that are executed by the system when the library attempts to locate or run the ngrok binary. This requires the attacker to have the ability to influence the configuration passed to the ngrok library within the application. As of the advisory date, no official patch has been released for these specific versions.

Affected products

  • bubenshchykov ngrok 4.3.3, 5.0.0-beta.2

Timeline

  • 2026-01-29: other: Vulnerability discovered and documented in Gist
  • 2026-05-18: disclosed: NVD publication date
  • 2026-05-18: advisory: GitHub Advisory published

References