CVE-2026-11572
HIGHDegit - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Title source: ruleDescription
Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exec() method by _cloneWithGit() and fetchRefs() functions. An attacker can execute arbitrary operating system commands as the process user by supplying a specially crafted git repository name.
References (4)
Core 4
Scores
CVSS v3
8.8
EPSS
0.0007
EPSS Percentile
21.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-77
CWE-78
Status
published
Products (2)
None/degit
< 2.8.6
None/degit
3.0.0 - 3.3.1
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026