Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-2w9p-xf5h-qwj3: pullit Command Injection vulnerability

The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval() is used on an attacker-supplied Git branch name.

ghsa
#vulnerability#nodejs#js#git

pullit Command Injection vulnerability

High severity GitHub Reviewed Published Mar 27, 2023 to the GitHub Advisory Database • Updated Mar 27, 2023

Related news

CVE-2018-25083: Snyk Vulnerability Database | Snyk

The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.