← Back

Async Git Project

async-git_project

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Async Git
async-git

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Async Git Project
1Async Git
Nov 21, 2024
Feb 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')
1Async Git Project
1Async Git
Nov 21, 2024
Jan 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.