VYPR

npm package

giting

pkg:npm/giting

Vulnerabilities (1)

  • CVE-2019-10802Feb 28, 2020
    affected <= 0.0.8

    giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is executed by the package without any validation.