CVE Feed

    Dashboard / CVE / CVE-2018-25083

    CVE-2018-25083

    The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.

    Published:Mar 27, 2023
    Last Modified:Feb 24, 2025
    EPS:Mar 27, 2023
    EPSS Score:0.01094
    CVSS Score:9.8

    Affected Products

    Vendor
    Pull It Project
    Product
    Pull It

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High