Junglewise Threat Intelligence

CVE-2025-57285: CodeceptJS command injection in emptyFolder utility

CVE-2025-57285 · Severity: low · CVSS 3.1 · Published 2025-09-08

Vendors: npm.

Executive brief

CodeceptJS is a testing framework used by developers to automate web and mobile application tests. A security flaw in how it handles folder cleanup allows an attacker to execute unauthorized commands on the system running the tests. This could lead to full system compromise, data theft, or the installation of malicious software during the automated testing process.

Technical details

A command injection vulnerability exists in CodeceptJS within the `emptyFolder` function located in `lib/utils.js`. The root cause is the direct concatenation of the user-controlled `directoryPath` parameter into an `execSync` call without proper sanitization or shell escaping. An attacker who can influence the configuration (specifically the `output` directory path) can inject shell metacharacters (e.g., `;`, `&&`, `|`) to execute arbitrary commands with the privileges of the Node.js process. This is particularly impactful in CI/CD environments where automated tests are executed. The issue is addressed in version 3.7.5.

Affected products

  • CodeceptJS codeceptjs 3.5.0 - 3.7.5-beta.18

Timeline

  • 2025-09-05: disclosed: Vulnerability details shared via GitHub Gist
  • 2025-09-08: advisory: GHSA and CVE published
  • 2025-09-21: patched: Fix merged into 3.x branch

References