Executive brief
gry is a Node.js library for interacting with Git repositories. A command injection vulnerability in versions before 6.0.0 allows an attacker with local access to execute arbitrary shell commands, potentially leading to unauthorized code execution or system compromise.
Technical details
A command injection vulnerability exists in the gry Node.js library (up to version 5.x) in an unknown component due to improper input validation on user-controlled data used in shell command construction (CWE-77). The vulnerability requires local access and likely requires an attacker to influence parameters passed to the library's Git operations. An authenticated or local attacker can inject arbitrary shell commands to achieve code execution with the privileges of the Node.js process. The issue was fixed in version 6.0.0 via commit 5108446c1e23960d65e8b973f1d9486f9f9dbd6c.
Affected products
- Ionică Bizău gry up to 5.x
Timeline
- 2023-01-11: disclosed
- 2020-04-20: patched: Fix merged; version 6.0.0 released