CVE-2025-66219Critical· 9.8▾ Midnightwillitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure ch…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.7%
willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether provided to the command-line flag, or is in user control in the target repository. At time of publication, no known fix is public.
willitmerge <= 0.2.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14225Medium· 6.3A vulnerability was determined in D-Link DCS-930L 1.15.04
CVE-2025-14707Critical· 9.8A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14706Critical· 9.8A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14705Critical· 9.8A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14659High· 8.8A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03
CVE-2025-11523Medium· 6.3A vulnerability was detected in Tenda AC7 15.03.06.44