Junglewise Threat Intelligence

CVE-2022-25853: semver-tags command injection in getGitTagsRemote

CVE-2022-25853 · Severity: low · CVSS 3.1 · Published 2023-02-06

Vendors: npm.

Executive brief

semver-tags is a Node.js library used to retrieve semantic version tags from Git and SVN repositories. A command injection vulnerability in the getGitTagsRemote function allows attackers to execute arbitrary system commands by supplying malicious input, potentially leading to full system compromise if the library is used in an automated or server-side context.

Technical details

The vulnerability is a command injection flaw (CWE-77, CWE-78) in the getGitTagsRemote function caused by improper input sanitization. The function constructs shell commands using user-controlled input without proper escaping, allowing an attacker with local access and low privileges to inject arbitrary commands. An authenticated local user can exploit this by providing crafted repository paths or parameters that break out of the intended command context. Successful exploitation allows remote code execution with the privileges of the process running the library. All versions up to and including 0.4.10 are affected; no public patch information is currently available.

Affected products

  • npm semver-tags 0 through 0.4.10

Timeline

  • 2023-02-06: advisory
  • 2022: other: CVE-2022-25853 assigned (year-only precision from CVE numbering)

References