CVE-2017-1000451
HIGHfs-git < 1.0.1 - Command Injection via buildCommand Method
Title source: llmDescription
fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec.
References (1)
Core 1
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/360
Scores
CVSS v3
7.8
EPSS
0.0077
EPSS Percentile
51.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (2)
fs-git_project/fs-git
< 1.0.1
npm/fs-git
0 - 1.0.2npm
Published
Jan 02, 2018
Tracked Since
Feb 18, 2026