CVE-2019-10776
CRITICALgit-diff-apply < 0.22.2 - OS Command Injection via RemoteUrl Parameter
Title source: llmDescription
In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.
References (3)
Core 3
Core References
Exploit, Patch, Third Party Advisory
https://snyk.io/vuln/SNYK-JS-GITDIFFAPPLY-540774
Patch, Third Party Advisory x_refsource_misc
https://github.com/kellyselden/git-diff-apply/commit/106d61d3ae723b4257c2a13e67b95eb40a27e0b5
Third Party Advisory x_refsource_confirm
https://snyk.io/vuln/SNYK-JS-GITDIFFAPPLY-540774%2C
Scores
CVSS v3
9.8
EPSS
0.0215
EPSS Percentile
79.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (2)
git-diff-apply_project/git-diff-apply
< 0.22.2
npm/git-diff-apply
0 - 0.22.2npm
Published
Jan 07, 2020
Tracked Since
Feb 18, 2026