GHSA-h42j-mrmp-9369
HIGHCVE-2023-26134Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo() fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject arguments to the git binary.
- Affected
- < 2.0.2
- Fixed in
- 2.0.2
- Published
- 2023-06-28
- Source
- github