Lucene search

K
osvGoogleOSV:GHSA-926X-M6M5-3MMP
HistoryFeb 09, 2022 - 10:50 p.m.

push-dir Enables OS Command Injection

2022-02-0922:50:06
Google
osv.dev
5
push-dir
os command injection
git command

EPSS

0.01

Percentile

83.3%

push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable opt.branch is not validated before being provided to the git command within index.js#L139. This could be abused by an attacker to inject arbitrary commands.

EPSS

0.01

Percentile

83.3%

Related for OSV:GHSA-926X-M6M5-3MMP