In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpdate to the version >=0.9.0
Due to the use of child_process.exec
when executing git commands, ungit allows for commands to be injection from user input fields that end up in an executed git command.
Source: Node Security Project