Critical severity9.8NVD Advisory· Published Apr 22, 2022· Updated Jun 17, 2026
CVE-2022-1440
CVE-2022-1440
Description
Command Injection vulnerability in [email protected] in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a --upload-pack command-line argument feature of git is also supported for git clone, which would then allow for any operating system command to be spawned by the attacker.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
git-interfacenpm | < 2.1.2 | 2.1.2 |
Affected products
3- cpe:2.3:a:git-interface_project:git-interface:*:*:*:*:*:node.js:*:*Range: <2.1.2
- yarkeev/yarkeev/git-interfacev5Range: unspecified
Patches
Vulnerability mechanics
References
4- github.com/yarkeev/git-interface/commit/f828aa790016fee3aa667f7b44cf94bf0aa8c60dnvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/cdc25408-d3c1-4a9d-bb45-33b12a715ca1nvdExploitMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-qffw-8wg7-h665ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-1440ghsaADVISORY
News mentions
0No linked articles in our index yet.