GHSA-wj6h-7chw-x4h2CriticalCVSS 9.8
Command injection in get-git-data
🔗 CVE IDs covered (1)
📋 Description
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.
🎯 Affected products1
- npm/get-git-data:<= 1.3.1