Critical severity9.8NVD Advisory· Published Feb 28, 2020· Updated Jun 17, 2026
CVE-2019-10803
CVE-2019-10803
Description
push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated before being provided to the "git" command within "index.js#L139". This could be abused by an attacker to inject arbitrary commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
push-dirnpm | <= 0.4.1 | — |
Affected products
3- push-dir/push-dirdescription
Patches
Vulnerability mechanics
References
4- snyk.io/vuln/SNYK-JS-PUSHDIR-559009nvdExploitThird Party AdvisoryWEB
- github.com/L33T-KR3W/push-dir/blob/master/index.jsnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-926x-m6m5-3mmpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10803ghsaADVISORY
News mentions
0No linked articles in our index yet.