VDB
Sign up
CRITICAL9.8

GHSA-6qpr-9mc5-7gch

Command Injection in async-git

Quick fix

GHSA-6qpr-9mc5-7gch — async-git: upgrade to the fixed version with the command below.

npm install async-git@1.13.2

Details

The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: `git.reset('atouch HACKEDb')`

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/async-git
Introduced in: 0Fixed in: 1.13.2
Fixnpm install async-git@1.13.2

References