Vulnerabilities/

CodeceptJS's incomprehensive sanitation can lead to Command Injection

Severity:
High

Description

CodeceptJS versions 3.5.0 through 3.7.5-beta.18 contain a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands.

Recommendation

Update the codeceptjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
codeceptjs
Anything's wrong? Let us know Last updated on September 23, 2025

This issue is available in SmartScanner Professional

See Pricing