{"id":"GHSA-5875-m6jq-vf78","summary":"Command injection in workspace-tools","details":"The package workspace-tools before 0.18.4 is vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.","aliases":["CVE-2022-25865","SNYK-JS-WORKSPACETOOLS-2421201"],"modified":"2026-07-08T06:49:42.022773950Z","published":"2022-05-14T00:01:08Z","database_specific":{"nvd_published_at":"2022-05-13T20:15:00Z","cwe_ids":["CWE-77"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-05-25T20:12:44Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25865"},{"type":"WEB","url":"https://github.com/microsoft/workspace-tools/pull/103"},{"type":"WEB","url":"https://github.com/microsoft/workspace-tools/commit/9bc7e65ce497f87e1f363fd47b8f802f3d3cd978"},{"type":"PACKAGE","url":"https://github.com/microsoft/workspace-tools"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-WORKSPACETOOLS-2421201"}],"affected":[{"package":{"name":"workspace-tools","ecosystem":"npm","purl":"pkg:npm/workspace-tools"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.18.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5875-m6jq-vf78/GHSA-5875-m6jq-vf78.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}