Critical severity9.1NVD Advisory· Published Feb 18, 2021· Updated Jun 17, 2026
CVE-2020-28490
CVE-2020-28490
Description
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
async-gitnpm | < 1.13.2 | 1.13.2 |
Affected products
3- async-git/async-gitdescription
- cpe:2.3:a:async-git_project:async-git:*:*:*:*:*:node.js:*:*Range: <1.13.2
Patches
Vulnerability mechanics
References
6- github.com/omrilotan/async-git/commit/d1950a5021f4e19d92f347614be0d85ce991510dnvdPatchThird Party AdvisoryWEB
- github.com/omrilotan/async-git/pull/14nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-ASYNCGIT-1064877nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-6qpr-9mc5-7gchghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28490ghsaADVISORY
- www.npmjs.com/package/async-gitghsaWEB
News mentions
0No linked articles in our index yet.