Loading HuntDB...

GHSA-62cx-5xj4-wfm4

GitHub Security Advisory

ggit is vulnerable to Command Injection via the fetchTags(branch) API

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe exec() Node.js child process API.

Affected Packages

npm ggit
Affected versions: 0 (last affected: 2.4.12)

Related CVEs

Key Information

GHSA ID
GHSA-62cx-5xj4-wfm4
Published
October 8, 2024 6:30 AM
Last Modified
October 8, 2024 2:38 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
ggit
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.