Critical severity9.8NVD Advisory· Published Jan 26, 2021· Updated Jun 17, 2026
CVE-2021-3190
CVE-2021-3190
Description
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
async-gitnpm | < 1.13.2 | 1.13.2 |
Affected products
3- async-git/async-gitdescription
- cpe:2.3:a:async-git_project:async-git:*:*:*:*:*:node.js:*:*Range: <1.13.2
Patches
Vulnerability mechanics
References
8- github.com/omrilotan/async-git/pull/13/commits/611823bd97dd41e9e8127c38066868ff9dcfa57anvdPatchThird Party AdvisoryWEB
- github.com/omrilotan/async-git/pull/13/commits/a5f45f58941006c4cc1699609383b533d9b92c6anvdPatchThird Party AdvisoryWEB
- github.com/omrilotan/async-git/pull/14nvdPatchThird Party AdvisoryWEB
- advisory.checkmarx.net/advisory/CX-2021-4772nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-6c3f-p5wp-34mhghsaADVISORY
- github.com/omrilotan/async-git/pull/13nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-3190ghsaADVISORY
- www.npmjs.com/package/async-gitghsaWEB
News mentions
0No linked articles in our index yet.