Executive brief
gitsome is a Git command-line utility tool. A vulnerability in how it processes repository tag names allows attackers to inject and execute arbitrary system commands when a user interacts with a malicious repository containing a specially crafted tag. This could lead to unauthorized access, data theft, or system compromise on the developer's machine.
Technical details
The vulnerability is an OS command injection (CWE-78) in gitsome through version 0.2.3. The root cause is insufficient sanitization of git tag names when processing them through a shell command. An attacker can craft a repository with a malicious tag name containing shell metacharacters and command injection payloads. When a user runs gitsome against this repository, the unsanitized tag name is passed to a shell command, allowing arbitrary command execution. The attack requires user interaction (opening/cloning the malicious repository) and network access to deliver the malicious repository. Patches should be available in versions after 0.2.3.
Affected products
- gitsome gitsome through 0.2.3
Timeline
- 2022-06-03: disclosed
- 2022-06-02: advisory: NVD publication