Description

SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper validation. This vulnerability bypasses a previous security fix and allows arbitrary command execution, potentially leading to exposure of sensitive environment variables and compromise of the runner environment. The vulnerability has been fixed in version 6.0.0. Users should upgrade to this version or later.

INFO

Published Date :

2025-09-26T16:24:55.126Z

Last Modified :

2025-09-26T17:31:50.867Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-59844 vulnerability.

Vendors Products
Microsoft
  • Windows
Sonarsource
  • Sonarqube Scanner

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability