Skip to main content
CRITICAL

CVE-2025-66219

CVSS v3

9.8

CRITICAL

EPSS Score

2.7 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether provided to the command-line flag, or is in user control in the target repository. At time of publication, no known fix is public.

Technical details

Published
2025-11-29

Frequently asked questions

What is CVE-2025-66219?

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user input, whether provided to the command-line flag, or is in user control in the target repository. At time of publication, no known fix is public.

Is CVE-2025-66219 actively exploited?

Active exploitation of CVE-2025-66219 has not been confirmed. Its EPSS score was 2.7% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-66219?

CVE-2025-66219 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2025-66219 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key