← Back to browse · API

CVE-2023-26134

Severity
CRITICAL
CVSS
9.8
EPSS
0.03638
Risk score
40.47
CISA KEV
No
PoC
No
Published
2023-06-28
Modified
2024-11-27
First seen
2026-08-07
Aliases
EUVD-2023-1813, GHSA-H42J-MRMP-9369
Products
n/a:git-commit-info 0 <2.0.2
Sources
euvd EUVD-2023-1813

Description

Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they control the hash content.

References