← Back to browse · API

CVE-2022-25766

Severity
HIGH
CVSS
8.8
EPSS
0.3389
Risk score
47.06
CISA KEV
No
PoC
No
Published
2022-03-21
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2022-1441, GHSA-HF8C-XR89-VFM5
Products
n/a:ungit unspecified <1.5.20
Sources
euvd EUVD-2022-1441

Description

The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs when calling the /api/fetch endpoint. User controlled values (remote and ref) are passed to the git fetch command. By injecting some git options it was possible to get arbitrary command execution.

References