Vulnerabilities |
4 via 4 paths |
|---|---|
Dependencies |
40 |
Source |
GitHub |
Find, fix and prevent vulnerabilities in your code.
critical severity
new
- Vulnerable module: @simple-git/argv-parser
- Introduced through: simple-git@3.36.0
Detailed paths
-
Introduced through: git-add-then-commit@Xunnamius/git-add-then-commit › simple-git@3.36.0 › @simple-git/argv-parser@1.1.1Remediation: Upgrade to simple-git@4.0.2.
Overview
Affected versions of this package are vulnerable to Command Injection via the prepareEnv function in parse-env.ts, which fails to recognize the VISUAL environment variable as a tracked unsafe editor key. Because VISUAL is not included in the GitEnvKeys map, it is silently discarded before collectConfigVulnerabilities inspects the environment, allowing an attacker-controlled VISUAL value to bypass the blockUnsafeOperationsPlugin spawn guard that would otherwise require the consumer to explicitly opt in to allowUnsafeEditor. This bypass permits an attacker who can influence the process environment to inject an arbitrary editor binary, potentially achieving remote code execution.
Remediation
Upgrade @simple-git/argv-parser to version 2.0.1 or higher.
References
critical severity
new
- Vulnerable module: simple-git
- Introduced through: simple-git@3.36.0
Detailed paths
-
Introduced through: git-add-then-commit@Xunnamius/git-add-then-commit › simple-git@3.36.0Remediation: Upgrade to simple-git@4.0.0.
Overview
simple-git is a light weight interface for running git commands in any node.js application.
Affected versions of this package are vulnerable to Arbitrary Command Injection via the blockUnsafeOperationsPlugin, which fails to block dangerous git options (such as --upload-pack, --receive-pack, and --exec) when abbreviated forms of those options are supplied by an attacker. An attacker who can influence the arguments passed to git commands can bypass the plugin's protections and achieve remote code execution.
Note: This is only exploitable when the consumer has not opted in via unsafe:{allowUnsafePack:true}, meaning the plugin is active but can be bypassed through abbreviated option names.
Remediation
Upgrade simple-git to version 4.0.0 or higher.
References
critical severity
new
- Vulnerable module: simple-git
- Introduced through: simple-git@3.36.0
Detailed paths
-
Introduced through: git-add-then-commit@Xunnamius/git-add-then-commit › simple-git@3.36.0Remediation: Upgrade to simple-git@4.0.0.
Overview
simple-git is a light weight interface for running git commands in any node.js application.
Affected versions of this package are vulnerable to Arbitrary Command Injection via the detect-vulnerable-config-writes path in the argv-parser package, where unsanitised arguments passed to git commands allow an attacker to inject arbitrary options through abbreviated flag handling. Because git accepts abbreviated long options by default, a remote attacker can supply a truncated flag that resolves to a dangerous option (such as --upload-pack) and achieve arbitrary command execution on the host running the library.
Remediation
Upgrade simple-git to version 4.0.0 or higher.
References
critical severity
new
- Vulnerable module: simple-git
- Introduced through: simple-git@3.36.0
Detailed paths
-
Introduced through: git-add-then-commit@Xunnamius/git-add-then-commit › simple-git@3.36.0Remediation: Upgrade to simple-git@4.0.0.
Overview
simple-git is a light weight interface for running git commands in any node.js application.
Affected versions of this package are vulnerable to Command Injection via the rebase command handler and the trailer.<token>.cmd/trailer.<token>.command configuration keys, which allow an attacker to inject the -x/--exec flag or a shell-executable trailer command into a spawned Git process. An attacker who can influence the arguments or configuration passed to simple-git can achieve arbitrary command execution on the host system.
Remediation
Upgrade simple-git to version 4.0.0 or higher.