CVE-2025-57283
The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-57283, https://github.com/browserstack/browserstack-local-nodejs/issues/168, https://gist.github.com/Dremig/b639c61541dd1482007dc7a5cd7fefb1, https://github.com/browserstack/browserstack-local-nodejs, https://www.npmjs.com
