High severity7.8NVD Advisory· Published Jan 2, 2018· Updated Jun 17, 2026
CVE-2017-1000451
CVE-2017-1000451
Description
fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fs-gitnpm | < 1.0.2 | 1.0.2 |
Affected products
2Patches
Vulnerability mechanics
References
4- nodesecurity.io/advisories/360nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-wp3j-gv53-4pg8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-1000451ghsaADVISORY
- github.com/vvakame/fs-git/commit/eb5f70efa5cfbff1ab299fa7daaa5de549243998ghsaWEB
News mentions
0No linked articles in our index yet.