Critical severity9.8NVD Advisory· Published Dec 7, 2021· Updated Jun 17, 2026
CVE-2021-44684
CVE-2021-44684
Description
naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, and is directly used by the exec function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github-todosnpm | <= 3.1.0 | — |
Affected products
3- naholyr/github-todosdescription
- cpe:2.3:a:github-todos_project:github-todos:*:*:*:*:*:*:*:*Range: <=3.1.0
Patches
Vulnerability mechanics
References
5- github.com/dwisiswant0/advisory/issues/5nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-792j-9wj3-j634ghsaADVISORY
- github.com/naholyr/github-todos/issues/34nvdIssue TrackingThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2021-44684ghsaADVISORY
- advisory.dw1.io/5ghsaWEB
News mentions
0No linked articles in our index yet.