OS Command Injection in node-glob - CVE-2025-64756
Published: December 9, 2025 / Updated: December 10, 2025
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing file names. A remote user can pass specially crafted filename to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Event Processing
watsonx Orchestrate Developer Edition
Storage Defender Copy Data Management
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Maximo Application Suite - Visual Inspection Component
IBM Business Automation Manager Open Editions
Maximo Application Suite Ai Service
Rational Performance Tester
DevOps Test Performance
IBM Event Endpoint Management
Developer Hub
IBM App Connect Enterprise
Kiali
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
Confluence Data Center
OpenShift Pipelines
Red Hat OpenShift AI (RHOAI)
Confluence Server
IBM Security QRadar Analyst Workflow
How to mitigate CVE-2025-64756
Event Processing - update to 1.4.7
watsonx Orchestrate Developer Edition - update to 2.3.0
Developer Hub - addressed in versions 1.7.4, 1.8.2
Kiali - addressed in versions 1.73.25, 2.4.11, 2.11.5, 2.17.2
Storage Defender Copy Data Management - update to 2.2.28.1
Guardium Data Security Center (GDSC) - update to 3.8.8
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.2
IBM Sterling Secure Proxy - addressed in versions 6.1.0.3, 6.2.0.3, 6.2.1.1
IBM Sterling External Authentication Server - addressed in versions 6.1.0.4, 6.1.1.1
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.19, 9.0.16, 9.1.7
IBM Business Automation Manager Open Editions - update to 9.3.1
Confluence Server - addressed in versions 9.0.2, 9.2.15, 10.2.7
Confluence Data Center - addressed in versions 9.0.2, 9.2.15, 10.2.7
Maximo Application Suite Ai Service - update to 9.1.11
DevOps Test Performance - update to 11.0.8
IBM Event Endpoint Management - update to 11.7.1
IBM App Connect Enterprise - addressed in versions 12.0.12.21, 13.0.6.0
OpenShift Pipelines - update to 1.19.4
Red Hat OpenShift AI (RHOAI) - update to 2.25.1
IBM Security QRadar Analyst Workflow - update to 3.0.1
External References
Related Security Bulletins
- OS command injection in isaacs node-glob
- Multiple vulnerabilities in Red Hat OpenShift Pipelines Release 1.19
- Multiple vulnerabilities in Kiali
- Multiple vulnerabilities in Red Hat OpenShift AI (RHOAI)
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow for IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Developer Hub 1.8
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for Glob
- IBM Event Endpoint Management update for Glob
- Multiple vulnerabilities in IBM Maximo AI Service
- Multiple vulnerabilities in Red Hat Developer Hub 1.7
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- IBM Event Processing update for Glob
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- Confluence Data Center and Server update for node-glob
- Multiple vulnerabilities in IBM watsonx Orchestrate Developer Edition
- IBM Maximo Application Suite - Visual Inspection Component update for Glob
- Multiple vulnerabilities in IBM Guardium Data Security Center
- IBM Storage Defender Copy Data Management update for Glob
- IBM DevOps Test Performance update for Glob