Miggo Logo

CVE-2025-59844: Argument injection vulnerability in SonarQube Scan Action

N/A

CVSS Score

Basic Information

EPSS Score
0.5316%
Published
9/26/2025
Updated
9/26/2025
KEV Status
No
Technology
TechnologyGitHub Actions

Technical Details

CVSS Vector
-
Package NameEcosystemVulnerable VersionsFirst Patched Version
SonarSource/sonarqube-scan-actionactions>= 4.0.0, < 6.0.06.0.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

* *omm*n* inj**tion vuln*r**ility *xists in Son*rQu** *it*u* **tion prior to v*.*.* w**n work*lows p*ss us*r-*ontroll** input to t** *r*s p*r*m*t*r on Win*ows runn*rs wit*out prop*r v*li**tion. T*is vuln*r**ility *yp*ss*s * pr*vious s**urity *ix *n*

Reasoning

No *n*lysis *v*il**l*