GHSA-qr32-j4j6-3m7r
Dashboard / Vulnerabilities / GHSA-qr32-j4j6-3m7r
Summary: Duplicate Advisory: Command Injection in fs-git
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-wp3j-gv53-4pg8. This link is maintained to preserve external references. ## Original Description Affected versions of `fs-git` do not sanitize strings passed into the `buildCommand` method, resulting in arbitrary code execution. ## Recommendation Update to version 1.0.2 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-16087, https://github.com/vvakame/fs-git/commit/eb5f70efa5cfbff1ab299fa7daaa5de549243998, https://github.com/vvakame/fs-git/commit/eb5f70efa5cfbff1ab299fa7daaa5de549243998#diff-13b5b151431c7e7a17f273559ed212d5, https://www.npmjs.com/advisories/360
Affected packages
Package
Name: fs-git
Purl: pkg:npm/fs-git
Affected ranges
Type: SEMVER
Events:
