Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Arbitrary Command Injection vulnerabilities in an interactive lesson.
Start learningUpgrade simple-git to version 4.0.0 or higher.
simple-git is a light weight interface for running git commands in any node.js application.
Affected versions of this package are vulnerable to Arbitrary Command Injection via the blockUnsafeOperationsPlugin, which fails to block dangerous git options (such as --upload-pack, --receive-pack, and --exec) when abbreviated forms of those options are supplied by an attacker. An attacker who can influence the arguments passed to git commands can bypass the plugin's protections and achieve remote code execution.
Note: This is only exploitable when the consumer has not opted in via unsafe:{allowUnsafePack:true}, meaning the plugin is active but can be bypassed through abbreviated option names.