{"id":"GHSA-fqfh-778m-2v32","summary":"GitHub CLI can execute a git binary from the current directory","details":"### Impact\nGitHub CLI depends on a `git.exe` executable being found in system `%PATH%` on Windows. However, if a malicious `.\\git.exe` or `.\\git.bat` is found in the current working directory at the time of running `gh`, the malicious command will be invoked instead of the system one.\n\nWindows users who run `gh` inside untrusted directories are affected.\n\n### Patches\nUsers should upgrade to GitHub CLI v1.2.1.\n\n### Workarounds\nOther than avoiding untrusted repositories, there is no workaround.\n\n### References\nhttps://github.com/golang/go/issues/38736","aliases":["GO-2022-0395"],"modified":"2024-08-21T14:57:06.656640Z","published":"2022-02-11T23:41:11Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-05-21T22:06:12Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/cli/cli/security/advisories/GHSA-fqfh-778m-2v32"}],"affected":[{"package":{"name":"github.com/cli/cli","ecosystem":"Go","purl":"pkg:golang/github.com/cli/cli"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-fqfh-778m-2v32/GHSA-fqfh-778m-2v32.json"}}],"schema_version":"1.9.0"}