Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-8jmw-wjr8-2x66: Command injection in git-clone

All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.

ghsa
#nodejs#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2022-25900

Command injection in git-clone

High severity GitHub Reviewed Published Jul 2, 2022 • Updated Jul 6, 2022

We are still processing this advisory. You may have affected repositories that are not yet on this list. Check back soon for more.

Package

npm git-clone (npm)

Affected versions

<= 0.2.0

Description

Related news

CVE-2022-25900: Command Injection vulnerability in [email protected]

All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.