The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) git_snapshot and (2) git_object.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.054
EPSS Ranking 89.5%