---
id: CVE-2025-59844
title: >-
  SonarQube Server and Cloud is a static analysis solution for continuous code
  quality and security inspection
summary: >-
  SonarQube Server and Cloud is a static analysis solution for continuous code
  quality and security inspection. A command injection vulnerability exists in
  SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when
  workflows pas…
severity: none
cwe:
  - CWE-78
published: '2025-09-26'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59844'
references:
  - url: >-
      https://community.sonarsource.com/t/sonarqube-scanner-github-action-v6/149281
    label: security-advisories@github.com
  - url: 'https://github.com/SonarSource/sonarqube-scan-action/releases/tag/v6.0.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/SonarSource/sonarqube-scan-action/security/advisories/GHSA-5xq9-5g24-4g6f
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.01469
epssPercentile: 0.72955
ingestedAt: '2026-10-09T12:53:27.788Z'
---

## Overview

SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper validation. This vulnerability bypasses a previous security fix and allows arbitrary command execution, potentially leading to exposure of sensitive environment variables and compromise of the runner environment. The vulnerability has been fixed in version 6.0.0. Users should upgrade to this version or later.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
