---
id: CVE-2025-66219
title: willitmerge is a command line tool to check if pull requests are mergeable
summary: >-
  willitmerge is a command line tool to check if pull requests are mergeable. In
  versions 0.2.1 and prior, there is a command Injection vulnerability in
  willitmerge. The vulnerability manifests in this package due to the use of
  insecure ch…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
vendor: dontkry
product: willitmerge
affected:
  - willitmerge <= 0.2.1
published: '2025-11-29'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66219'
references:
  - url: >-
      https://github.com/shama/willitmerge/blob/2fe91d05191fb05ac6da685828d109a3a5885028/lib/willitmerge.js#L189-L197
    label: security-advisories@github.com
  - url: >-
      https://github.com/shama/willitmerge/security/advisories/GHSA-j9wj-m24m-7jj6
    label: security-advisories@github.com
  - url: >-
      https://github.com/shama/willitmerge/security/advisories/GHSA-j9wj-m24m-7jj6
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.02659
epssPercentile: 0.85214
ingestedAt: '2026-10-07T20:46:46.737Z'
---

## Overview

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether provided to the command-line flag, or is in user control in the target repository. At time of publication, no known fix is public.

## Affected

- `willitmerge <= 0.2.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
