Description
Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific schema, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options.
Remediation
References
https://gist.github.com/lirantal/14c3686370a86461f555d3f0703e02f9
https://github.com/kucherenko/blamer/commit/0965877f115753371a2570f10a63c455d2b2cde3
https://security.snyk.io/vuln/SNYK-JS-BLAMER-5731318
Related Vulnerabilities
CVE-2021-4245 Vulnerability in npm package rfc6902
CVE-2021-43138 Vulnerability in npm package async
CVE-2018-19837 Vulnerability in npm package node-sass
CVE-2023-26474 Vulnerability in maven package org.xwiki.platform:xwiki-platform-legacy-oldcore
CVE-2018-18628 Vulnerability in maven package ro.pippo:pippo-core