Vulnerability Description
The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Browserstack | Browserstack-Local | 1.5.8 |
Related Weaknesses (CWE)
References
- https://gist.github.com/Dremig/b639c61541dd1482007dc7a5cd7fefb1Third Party Advisory
- https://www.npmjs.comProduct
FAQ
What is CVE-2025-57283?
CVE-2025-57283 is a vulnerability with a CVSS score of 7.8 (HIGH). The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.
How severe is CVE-2025-57283?
CVE-2025-57283 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-57283?
Check the references section above for vendor advisories and patch information. Affected products include: Browserstack Browserstack-Local.