CVE-2019-10802

CRITICAL

giting < 0.0.8 - OS Command Injection via Pull Function Repo Argument

Title source: llm
STIX 2.1

Description

giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is executed by the package without any validation.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-GITING-559008

Scores

CVSS v3 9.8
EPSS 0.0240
EPSS Percentile 81.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
mangoraft/giting < 0.0.8
npm/giting 0npm
Published Feb 28, 2020
Tracked Since Feb 18, 2026