MEDIUM6.6
GHSA-9gqr-xp86-f87h
Code injection in npm git
Details
All versions of package git are vulnerable to Remote Code Execution (RCE) due to missing sanitization in the Git.git method, which allows execution of OS commands rather than just git commands. At this time, there is no known workaround. There has been no patch released.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/git
Introduced in:
0No fixed version published yet for git (npm). Pin to a known-safe version or switch to an alternative.