{"id":"GHSA-3p94-vj97-fm4q","summary":"OS Command Injection in fsa","details":"fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.js#63' can be controlled by users without any sanitization to inject arbitrary commands.","aliases":["CVE-2020-7615"],"modified":"2026-03-13T21:56:24.519068Z","published":"2021-12-09T19:56:44Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-05-25T16:28:38Z","nvd_published_at":"2020-04-07T14:15:00Z","cwe_ids":["CWE-78"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7615"},{"type":"WEB","url":"https://github.com/gregof/fsa/blob/master/lib/rep.js#L12"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-FSA-564118"}],"affected":[{"package":{"name":"fsa","ecosystem":"npm","purl":"pkg:npm/fsa"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-3p94-vj97-fm4q/GHSA-3p94-vj97-fm4q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}