Executive brief
ggit is a JavaScript library for running Git commands. The clone() function fails to properly sanitize URL input, allowing an attacker to inject arbitrary command-line arguments to the underlying git binary and execute arbitrary system commands during a clone operation.
Technical details
ggit contains an argument injection vulnerability (CWE-88) in the clone() API that fails to validate URL schemes or sanitize user input before passing arguments to the underlying git binary. The library does not use the double-dash (--) POSIX convention to mark the end of command-line options, allowing attackers to inject arbitrary git arguments such as --upload-pack with embedded command substitution (e.g., $(command)). This enables remote code execution when a user-controlled URL is passed to clone(). The vulnerability affects all versions through 2.4.12 and requires no authentication or user interaction beyond calling the clone() function with a malicious URL parameter.
Affected products
- bahmutov ggit through 2.4.12
Timeline
- 2024-10-08: disclosed
- 2024-10-08: kev added