GHSA-h42j-mrmp-9369
Dashboard / Vulnerabilities / GHSA-h42j-mrmp-9369
Summary: git-commit-info vulnerable to Command Injection
Details: Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo() fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject arguments to the git binary.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-26134, https://github.com/JPeer264/node-git-commit-info/issues/24, https://github.com/JPeer264/node-git-commit-info/commit/f7c491ede51f886a988af9b266797cb24591d18c, https://github.com/JPeer264/node-git-commit-info, https://security.snyk.io/vuln/SNYK-JS-GITCOMMITINFO-5740174, https://www.npmjs.com/package/execa/v/5.1.0#execacommandcommand-options
Affected packages
Package
Name: git-commit-info
Purl: pkg:npm/git-commit-info
Affected ranges
Type: SEMVER
Events:
