{"id":"GHSA-8jmw-wjr8-2x66","summary":"Command injection in git-clone","details":"All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the `--upload-pack` feature of git.\n\n## Credits\n\nCredit to @lirantal for discovering this vulnerability.","aliases":["CVE-2022-25900"],"modified":"2026-03-13T21:57:04.012790Z","published":"2022-07-02T00:00:19Z","database_specific":{"github_reviewed_at":"2022-07-06T19:51:34Z","nvd_published_at":"2022-07-01T20:15:00Z","cwe_ids":["CWE-77","CWE-88"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25900"},{"type":"WEB","url":"https://github.com/jaz303/git-clone/commit/fd330459593aef7c7a8c54d786e3c4d5722749f9"},{"type":"WEB","url":"https://gist.github.com/lirantal/9441f3a1212728476f7a6caa4acb2ccc"},{"type":"PACKAGE","url":"https://github.com/jaz303/git-clone"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-GITCLONE-2434308"}],"affected":[{"package":{"name":"git-clone","ecosystem":"npm","purl":"pkg:npm/git-clone"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-8jmw-wjr8-2x66/GHSA-8jmw-wjr8-2x66.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}