VDB
Sign up
CRITICAL9.8

GHSA-3x62-x456-q2vm

OS Command Injection in git-pull-or-clone

Quick fix

GHSA-3x62-x456-q2vm — git-pull-or-clone: upgrade to the fixed version with the command below.

npm install git-pull-or-clone@2.0.2

Details

The package git-pull-or-clone before 2.0.2 is vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection. ## Credits

Credit @lirantal for discovering this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/git-pull-or-clone
Introduced in: 0Fixed in: 2.0.2
Fixnpm install git-pull-or-clone@2.0.2

References