{"id":"GHSA-5xq9-5g24-4g6f","summary":"Argument injection vulnerability in SonarQube Scan Action","details":"A command injection vulnerability exists in SonarQube GitHub Action prior to v6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper validation. This vulnerability bypasses a previous security fix and allows arbitrary command execution, potentially leading to exposure of sensitive environment variables and compromise of the runner environment.\n\n\n### Patches\nThe vulnerability has been fixed in version v6.0.0. Users should upgrade to this version or later.\n\n\n### Credits\nFrancois Lajeunesse-Robert (Boostsecurity.io)\n\n\n### References\n- Community Post: https://community.sonarsource.com/t/sonarqube-scanner-github-action-v6/149281 \n- Fix release: https://github.com/SonarSource/sonarqube-scan-action/releases/tag/v6.0.0","aliases":["CVE-2025-59844"],"modified":"2026-09-15T06:34:14.407562151Z","published":"2025-09-26T13:01:10Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-09-26T13:01:10Z","nvd_published_at":"2025-09-26T17:15:36Z","cwe_ids":["CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/SonarSource/sonarqube-scan-action/security/advisories/GHSA-5xq9-5g24-4g6f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59844"},{"type":"WEB","url":"https://community.sonarsource.com/t/sonarqube-scanner-github-action-v6/149281"},{"type":"PACKAGE","url":"https://github.com/SonarSource/sonarqube-scan-action"},{"type":"WEB","url":"https://github.com/SonarSource/sonarqube-scan-action/releases/tag/v6.0.0"}],"affected":[{"package":{"name":"SonarSource/sonarqube-scan-action","ecosystem":"GitHub Actions"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"6.0.0"}]},{"type":"GIT","repo":"https://github.com/SonarSource/sonarqube-scan-action","events":[{"introduced":"94d4f8ac4aaefccd7fb84bff00b0aeb2d65fcd49"},{"fixed":"fd88b7d7ccbaefd23d8f36f73b59db7a3d246602"}]}],"versions":["v4.2.1","v5.3.1","v5.3.0","v5.2.0","v5.2","v5.1.0","v5.1","v5.0.0","v5.0","v4.2.0","v4.1.0","v4.1","v4.0.0","v4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-5xq9-5g24-4g6f/GHSA-5xq9-5g24-4g6f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}