Junglewise Threat Intelligence

CVE-2023-26134: git-commit-info command injection vulnerability

CVE-2023-26134 · Severity: low · CVSS 3.1 · Published 2023-06-28

Vendors: npm.

Executive brief

git-commit-info is a Node.js library that retrieves information about Git commits. The package fails to properly validate the commit parameter, allowing attackers who control the commit hash input to inject arbitrary Git command arguments and execute malicious commands on systems running vulnerable code.

Technical details

The vulnerability is a command injection flaw (CWE-77, CWE-78) in the gitCommitInfo() function where the unsanitized commit parameter is passed directly into a sensitive command execution API without validation. An attacker who can control the commit parameter value (e.g., via application input) can inject shell metacharacters and additional arguments to the underlying git binary. No authentication or special preconditions are required; exploitation depends on whether the application passes untrusted input to the vulnerable function. The vulnerability affects all versions before 2.0.2, which is now available as a patch.

Affected products

  • JPeer264 git-commit-info before 2.0.2

Timeline

  • 2023-06-28: disclosed: Vulnerability published in OSV database
  • 2023-06-28: advisory: GitHub Security Advisory GHSA-h42j-mrmp-9369 released
  • 2023-06-28: patched: Fix available in version 2.0.2

References