VDB
Sign up
CRITICAL9.8

GHSA-6c3f-p5wp-34mh

OS Command Injection in async-git

Quick fix

GHSA-6c3f-p5wp-34mh — async-git: upgrade to the fixed version with the command below.

npm install async-git@1.13.2

Details

The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. Ensure to sanitize untrusted user input before passing it to one of the vulnerable functions as a workaround or update async-git to version 1.13.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/async-git
Introduced in: 0Fixed in: 1.13.2
Fixnpm install async-git@1.13.2

References