CVE-2025-59844 is a low severity vulnerability with a CVSS score of 0.0. No known exploits currently, and patches are available.
Very low probability of exploitation
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
A command injection vulnerability exists in SonarQube GitHub Action prior to v6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper validation. This vulnerability bypasses a previous security fix and allows arbitrary command execution, potentially leading to exposure of sensitive environment variables and compromise of the runner environment.
The vulnerability has been fixed in version v6.0.0. Users should upgrade to this version or later.
Francois Lajeunesse-Robert (Boostsecurity.io)
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.