VYPR
Medium severity5.3NVD Advisory· Published Oct 1, 2024· Updated Apr 15, 2026

CVE-2024-21531

CVE-2024-21531

Description

All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process variable of the gitShallowClone function.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
git-shallow-clonenpm
<= 0.0.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.