Headline
GHSA-2w9p-xf5h-qwj3: pullit Command Injection vulnerability
The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval()
is used on an attacker-supplied Git branch name.
pullit Command Injection vulnerability
High severity GitHub Reviewed Published Mar 27, 2023 to the GitHub Advisory Database • Updated Mar 27, 2023
Related news
CVE-2018-25083: Snyk Vulnerability Database | Snyk
The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.