Vulnerability Details CVE-2023-26134
Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they control the hash content.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.8%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-26134
-
cpe:2.3:a:git-commit-info_project:git-commit-info:-
-
cpe:2.3:a:git-commit-info_project:git-commit-info:1.0.0
-
cpe:2.3:a:git-commit-info_project:git-commit-info:1.0.1
-
cpe:2.3:a:git-commit-info_project:git-commit-info:1.1.0
-
cpe:2.3:a:git-commit-info_project:git-commit-info:2.0.0
-
cpe:2.3:a:git-commit-info_project:git-commit-info:2.0.1