Junglewise Threat Intelligence

CVE-2022-25766: ungit command injection via argument injection in /api/fetch

CVE-2022-25766 · Severity: low · CVSS 3.1 · Published 2022-03-22

Vendors: npm.

Executive brief

ungit is a Git user interface that runs as a web application. A vulnerability in its /api/fetch endpoint allows authenticated users to execute arbitrary commands on the server by injecting git options into fetch parameters, leading to complete system compromise through remote code execution.

Technical details

The vulnerability is a command injection flaw (CWE-77) in the /api/fetch endpoint. User-controlled parameters (remote and ref) are concatenated directly into a git fetch command without proper escaping. Although the code uses Node.js spawn (which avoids shell injection in typical cases), the git fetch subcommand accepts the --upload-pack option that can specify an arbitrary command to execute. An authenticated user can inject --upload-pack="malicious command" as the remote parameter to achieve arbitrary command execution with the privileges of the ungit process. The vulnerability is network-reachable and requires valid authentication to exploit. Versions before 1.5.20 are affected; the fix adds -- to separate user input from options.

Affected products

  • ungit ungit before 1.5.20

Timeline

  • 2022-03-21: disclosed
  • 2022-03-18: patched: PR #1510 merged; version 1.5.20 released
  • 2022-03-22: advisory

References

Related threats