VYPR
High severity8.8NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026

CVE-2026-11572

CVE-2026-11572

Description

Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exec() method by _cloneWithGit() and fetchRefs() functions. An attacker can execute arbitrary operating system commands as the process user by supplying a specially crafted git repository name.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Rich Harris/Degitreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <2.8.6, >=3.0.0 and <3.3.1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.