GHSA-62cx-5xj4-wfm4
GitHub Security Advisory
ggit is vulnerable to Command Injection via the fetchTags(branch) API
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe exec() Node.js child process API.
Affected Packages
npm
ggit
Affected versions:
0
(last affected: 2.4.12)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 15, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.