Junglewise Threat Intelligence

CVE-2024-21533: ggit argument injection in clone() API

CVE-2024-21533 · Severity: low · CVSS 3.1 · Published 2024-10-08

Vendors: npm.

Executive brief

ggit is a JavaScript library for running Git commands. The clone() function fails to properly sanitize URL input, allowing an attacker to inject arbitrary command-line arguments to the underlying git binary and execute arbitrary system commands during a clone operation.

Technical details

ggit contains an argument injection vulnerability (CWE-88) in the clone() API that fails to validate URL schemes or sanitize user input before passing arguments to the underlying git binary. The library does not use the double-dash (--) POSIX convention to mark the end of command-line options, allowing attackers to inject arbitrary git arguments such as --upload-pack with embedded command substitution (e.g., $(command)). This enables remote code execution when a user-controlled URL is passed to clone(). The vulnerability affects all versions through 2.4.12 and requires no authentication or user interaction beyond calling the clone() function with a malicious URL parameter.

Affected products

  • bahmutov ggit through 2.4.12

Timeline

  • 2024-10-08: disclosed
  • 2024-10-08: kev added

References

Related threats