push-dir Enables OS Command Injection
Critical severity
GitHub Reviewed
Published
Feb 9, 2022
to the GitHub Advisory Database
•
Updated Sep 11, 2023
Description
Published by the National Vulnerability Database
Feb 28, 2020
Reviewed
Apr 9, 2021
Published to the GitHub Advisory Database
Feb 9, 2022
Last updated
Sep 11, 2023
push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable
opt.branch
is not validated before being provided to thegit
command within index.js#L139. This could be abused by an attacker to inject arbitrary commands.References