VDB
Sign up
HIGH8.1

GHSA-8jmw-wjr8-2x66

Command injection in git-clone

Details

All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the `--upload-pack` feature of git.

## Credits

Credit to @lirantal for discovering this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/git-clone
Introduced in: 0

No fixed version published yet for git-clone (npm). Pin to a known-safe version or switch to an alternative.

References