CVE-2019-5485
CRITICALGitlabhook - OS Command Injection
Title source: ruleDescription
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.
Exploits (1)
exploitdb
WORKING POC
by Semen Alexandrovich Lyhin · textwebappsjson
https://www.exploit-db.com/exploits/47420
Scores
CVSS v3
10.0
EPSS
0.4963
EPSS Percentile
97.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (2)
gitlabhook_project/gitlabhook
0.0.17
npm/gitlabhook
0npm
Published
Sep 13, 2019
Tracked Since
Feb 18, 2026