Critical severity10.0NVD Advisory· Published Sep 13, 2019· Updated Jun 17, 2026
CVE-2019-5485
CVE-2019-5485
Description
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gitlabhooknpm | <= 0.0.17 | — |
Affected products
3- cpe:2.3:a:gitlabhook_project:gitlabhook:0.0.17:*:*:*:*:node.js:*:*
- gitlabhook/gitlabhookdescription
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/154598/NPMJS-gitlabhook-0.0.17-Remote-Command-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- hackerone.com/reports/685447nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-549f-73hh-mj38ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-5485ghsaADVISORY
News mentions
0No linked articles in our index yet.