chore(monorepo): update dependency glob to v11.1.0 [security]#177
chore(monorepo): update dependency glob to v11.1.0 [security]#177renovate[bot] wants to merge 1 commit into
Conversation
192c2fc to
7fe50e0
Compare
7fe50e0 to
e0351de
Compare
e0351de to
26f2d93
Compare
26f2d93 to
cbe1d14
Compare
cbe1d14 to
325972e
Compare
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
325972e to
d6afea5
Compare
d6afea5 to
333b8ea
Compare
333b8ea to
e8705f7
Compare
e8705f7 to
b92efe0
Compare
b92efe0 to
fad88cb
Compare
fad88cb to
c7905c0
Compare
c7905c0 to
996a99a
Compare
996a99a to
e0f41f1
Compare
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
This PR contains the following updates:
11.0.0→11.1.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
glob CLI: Command injection via -c/--cmd executes matches with shell:true
CVE-2025-64756 / GHSA-5j98-mcp5-4vw2
More information
Details
Summary
The glob CLI contains a command injection vulnerability in its
-c/--cmdoption that allows arbitrary command execution when processing files with malicious names. Whenglob -c <command> <patterns>is used, matched filenames are passed to a shell withshell: true, enabling shell metacharacters in filenames to trigger command injection and achieve arbitrary code execution under the user or CI account privileges.Details
Root Cause:
The vulnerability exists in
src/bin.mts:277where the CLI collects glob matches and executes the supplied command usingforegroundChild()withshell: true:Technical Flow:
glob -c <command> <pattern>shell: trueAffected Component:
glob(),globSync(), streams/iterators) is not affectedAttack Surface:
$(), backticks,;,&,|, etc.glob -con untrusted contentPoC
Setup Malicious File:
Trigger Vulnerability:
Result:
$(touch injected_poc)in the filename is evaluated by the shellinjected_pocis created, proving command executionAdvanced Payload Examples:
Data Exfiltration:
Reverse Shell:
Environment Variable Harvesting:
Impact
Arbitrary Command Execution:
Real-World Attack Scenarios:
1. CI/CD Pipeline Compromise:
glob -cto process files (linting, testing, deployment)2. Developer Workstation Attack:
glob -cfor file processing3. Automated Processing Systems:
4. Supply Chain Poisoning:
Platform-Specific Risks:
Affected Products
src/bin.mts)-c/--cmdoption)Scope Limitation:
glob(),globSync(), async iterators) are safe-c/--cmdoption is vulnerableRemediation
glob@10.5.0,glob@11.1.0, or higher, as soon as possible.globCLI actions fail, then convert commands containing positional arguments, to use the--cmd-arg/-goption instead.--shellto maintainshell:truebehavior until glob v12, but take care to ensure that no untrusted contents can possibly be encountered in the file path results.Severity
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
isaacs/node-glob (glob)
v11.1.0Compare Source
v11.0.3Compare Source
v11.0.2Compare Source
v11.0.1Compare Source
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.