Critical severity9.8NVD Advisory· Published May 1, 2022· Updated Jun 17, 2026
CVE-2022-24437
CVE-2022-24437
Description
The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
git-pull-or-clonenpm | < 2.0.2 | 2.0.2 |
Affected products
3- cpe:2.3:a:git-pull-or-clone_project:git-pull-or-clone:*:*:*:*:*:node.js:*:*Range: <2.0.2
- git-pull-or-clone/git-pull-or-clonedescription
Patches
Vulnerability mechanics
References
5- github.com/feross/git-pull-or-clone/commit/f9ce092be13cc32e685dfa26e7705e9c6e3108a3nvdPatchThird Party AdvisoryWEB
- gist.github.com/lirantal/327e9dd32686991b5a1fa6341aac2e7bnvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-GITPULLORCLONE-2434307nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-3x62-x456-q2vmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-24437ghsaADVISORY
News mentions
0No linked articles in our index yet.