VDB
Sign up
MEDIUM6.6

GHSA-9gqr-xp86-f87h

Code injection in npm git

Details

All versions of package git are vulnerable to Remote Code Execution (RCE) due to missing sanitization in the Git.git method, which allows execution of OS commands rather than just git commands. At this time, there is no known workaround. There has been no patch released.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/git
Introduced in: 0

No fixed version published yet for git (npm). Pin to a known-safe version or switch to an alternative.

References