git-ls-remote@0.0.2 vulnerabilities

A very simple interface to git ls-remote

Direct Vulnerabilities

Known vulnerabilities in the git-ls-remote package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Shell Command Injection

git-ls-remote is an npm package used for listing references in a remote git repository. Vulnerable versions of the package pass the git url argument to the exec function without sanitisation. An attacker can use this to inject malicious shell commands to disrupt server operation or obtain sensitive information.

How to fix Shell Command Injection?

Upgrade git-ls-remote to version 0.2.0 or higher.

<0.2.0