VDB
Sign up
CRITICAL9.8

GHSA-3fxp-vwxm-2r5p

Command injection in gitlogplus

Details

All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/gitlogplus
Introduced in: 0

No fixed version published yet for gitlogplus (npm). Pin to a known-safe version or switch to an alternative.

References