VYPR
High severity7.3NVD Advisory· Published Oct 8, 2024· Updated Apr 15, 2026

CVE-2024-21532

CVE-2024-21532

Description

All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe exec() Node.js child process API.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ggitnpm
<= 2.4.12

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.