ejson2env has insufficient input sanitization
Published May 21, 2025
6.6
MEDIUMCVSS 3.1
EPSS 1.32%
Description
ejson2env allows users to decrypt EJSON secrets and export them as environment variables. Prior to version 2.0.8, the `ejson2env` tool has a vulnerability related to how it writes to `stdout`. Specifically, the tool is intended to write an export statement for environment variables and their values. However, due to inadequate output sanitization, there is a potential risk where variable names or values may include malicious content, resulting in additional unintended commands being output to `stdout`. If this output is improperly utilized in further command execution, it could lead to command injection, allowing an attacker to execute arbitrary commands on the host system. Version 2.0.8 sanitizes output during decryption. Other mitigations involve avoiding use of `ejson2env` to decrypt untrusted user secrets and/or avoiding evaluating or executing the direct output from `ejson2env` without removing nonprintable characters.
Affected products
-
- Version < 2.0.8StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/Shopify/ejson2env/v2
Go
Introduced 0 Fixed 2.0.8ejson2env
RubyGems
Introduced 0 Fixed 2.0.8github.com/Shopify/ejson2env
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/Shopify/ejson2env/v2 | 0 | 2.0.8 |
| RubyGems | ejson2env | 0 | 2.0.8 |
| Go | github.com/Shopify/ejson2env | 0 | not fixed |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 21, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.32% (0.01317) | 69.73th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.33% (0.01334) | 67.37th | v5 (v2026.06.15) |
| May 22, 2025 | 0.11% (0.00106) | 30.04th | v4 (v2025.03.14) |
References (5)
- https://github.com/Shopify/ejson2env/commit/592b3ceea967fee8b064e70983e8cec087b6d840 x_refsource_MISC
- https://github.com/Shopify/ejson2env/security/advisories/GHSA-2c47-m757-32g6 x_refsource_CONFIRM
- https://github.com/advisories/GHSA-2c47-m757-32g6 Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ejson2env/CVE-2025-48069.yml
- https://nvd.nist.gov/vuln/detail/CVE-2025-48069
Change history (0)
No recorded changes yet.