GHSA-wj6h-7chw-x4h2CriticalCVSS 9.8

Command injection in get-git-data

Published
May 10, 2021
Last Modified
July 6, 2026

🔗 CVE IDs covered (1)

📋 Description

get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.

🎯 Affected products1

  • npm/get-git-data:<= 1.3.1

🔗 References (4)