GHSA-6qpr-9mc5-7gch
CRITICALCVE-2020-28490The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')
- Affected
- < 1.13.2
- Fixed in
- 1.13.2
- Weakness
- CWE-78
- Published
- 2021-04-12
- Source
- github