OS Command Injection in node-glob - CVE-2025-64756

 

OS Command Injection in node-glob - CVE-2025-64756

Published: December 9, 2025 / Updated: December 10, 2025


Vulnerability identifier: #VU119401
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-64756
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation when processing file names. A remote user can pass specially crafted filename to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

node-glob
Event Processing
watsonx Orchestrate Developer Edition
Storage Defender Copy Data Management
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Maximo Application Suite - Visual Inspection Component
IBM Business Automation Manager Open Editions
Maximo Application Suite Ai Service
Rational Performance Tester
DevOps Test Performance
IBM Event Endpoint Management
Developer Hub
IBM App Connect Enterprise
Kiali
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
Confluence Data Center
OpenShift Pipelines
Red Hat OpenShift AI (RHOAI)
Confluence Server
IBM Security QRadar Analyst Workflow

How to mitigate CVE-2025-64756

Install updates from vendor's website.

node-glob - addressed in versions 10.5.0, 11.1.0
Event Processing - update to 1.4.7
watsonx Orchestrate Developer Edition - update to 2.3.0
Developer Hub - addressed in versions 1.7.4, 1.8.2
Kiali - addressed in versions 1.73.25, 2.4.11, 2.11.5, 2.17.2
Storage Defender Copy Data Management - update to 2.2.28.1
Guardium Data Security Center (GDSC) - update to 3.8.8
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.2
IBM Sterling Secure Proxy - addressed in versions 6.1.0.3, 6.2.0.3, 6.2.1.1
IBM Sterling External Authentication Server - addressed in versions 6.1.0.4, 6.1.1.1
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.19, 9.0.16, 9.1.7
IBM Business Automation Manager Open Editions - update to 9.3.1
Confluence Server - addressed in versions 9.0.2, 9.2.15, 10.2.7
Confluence Data Center - addressed in versions 9.0.2, 9.2.15, 10.2.7
Maximo Application Suite Ai Service - update to 9.1.11
DevOps Test Performance - update to 11.0.8
IBM Event Endpoint Management - update to 11.7.1
IBM App Connect Enterprise - addressed in versions 12.0.12.21, 13.0.6.0
OpenShift Pipelines - update to 1.19.4
Red Hat OpenShift AI (RHOAI) - update to 2.25.1
IBM Security QRadar Analyst Workflow - update to 3.0.1

External References

Related Security Bulletins