High severity8.1NVD Advisory· Published Jul 1, 2022· Updated Jun 17, 2026
CVE-2022-25900
CVE-2022-25900
Description
All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
git-clonenpm | <= 0.2.0 | — |
Affected products
2- cpe:2.3:a:git-clone_project:git-clone:*:*:*:*:*:node.js:*:*
Patches
Vulnerability mechanics
References
5- gist.github.com/lirantal/9441f3a1212728476f7a6caa4acb2cccnvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-GITCLONE-2434308nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-8jmw-wjr8-2x66ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25900ghsaADVISORY
- github.com/jaz303/git-clone/commit/fd330459593aef7c7a8c54d786e3c4d5722749f9ghsaWEB
News mentions
0No linked articles in our index yet.