Junglewise Threat Intelligence

CVE-2021-34081: gitsome OS Command Injection via crafted tag name

CVE-2021-34081 · Severity: low · CVSS 3.1 · Published 2022-06-03

Vendors: npm.

Executive brief

gitsome is a Git command-line utility tool. A vulnerability in how it processes repository tag names allows attackers to inject and execute arbitrary system commands when a user interacts with a malicious repository containing a specially crafted tag. This could lead to unauthorized access, data theft, or system compromise on the developer's machine.

Technical details

The vulnerability is an OS command injection (CWE-78) in gitsome through version 0.2.3. The root cause is insufficient sanitization of git tag names when processing them through a shell command. An attacker can craft a repository with a malicious tag name containing shell metacharacters and command injection payloads. When a user runs gitsome against this repository, the unsanitized tag name is passed to a shell command, allowing arbitrary command execution. The attack requires user interaction (opening/cloning the malicious repository) and network access to deliver the malicious repository. Patches should be available in versions after 0.2.3.

Affected products

  • gitsome gitsome through 0.2.3

Timeline

  • 2022-06-03: disclosed
  • 2022-06-02: advisory: NVD publication

References