Critical severity9.8NVD Advisory· Published Jun 28, 2023· Updated Jun 17, 2026
CVE-2023-26134
CVE-2023-26134
Description
Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they control the hash content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
git-commit-infonpm | < 2.0.2 | 2.0.2 |
Affected products
3- cpe:2.3:a:git-commit-info_project:git-commit-info:*:*:*:*:*:node.js:*:*Range: <2.0.2
- git-commit-info/git-commit-infodescription
Patches
Vulnerability mechanics
References
6- github.com/JPeer264/node-git-commit-info/commit/f7c491ede51f886a988af9b266797cb24591d18cnvdPatchWEB
- github.com/JPeer264/node-git-commit-info/issues/24nvdExploitIssue TrackingWEB
- security.snyk.io/vuln/SNYK-JS-GITCOMMITINFO-5740174nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-h42j-mrmp-9369ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26134ghsaADVISORY
- www.npmjs.com/package/execa/v/5.1.0ghsaWEB
News mentions
0No linked articles in our index yet.