Description
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')
Remediation
References
https://github.com/omrilotan/async-git/commit/d1950a5021f4e19d92f347614be0d85ce991510d
https://github.com/omrilotan/async-git/pull/14
https://snyk.io/vuln/SNYK-JS-ASYNCGIT-1064877
Related Vulnerabilities
CVE-2022-23945 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2022-21169 Vulnerability in npm package express-xss-sanitizer
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2022-44262 Vulnerability in maven package org.ff4j:ff4j-core
CVE-2020-7616 Vulnerability in npm package express-mock-middleware