VDB
Sign up
CRITICAL9.8

GHSA-5875-m6jq-vf78

Command injection in workspace-tools

Quick fix

GHSA-5875-m6jq-vf78 — workspace-tools: upgrade to the fixed version with the command below.

npm install workspace-tools@0.18.4

Details

The package workspace-tools before 0.18.4 is vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/workspace-tools
Introduced in: 0Fixed in: 0.18.4
Fixnpm install workspace-tools@0.18.4

References