Executive brief
check-branches is a command-line tool used to check for Git branch conflicts in repositories, particularly useful in CI/CD pipelines and team environments. The vulnerability allows attackers to execute arbitrary commands on systems running the tool by crafting malicious Git branch names, potentially leading to unauthorized code execution, data theft, or system compromise.
Technical details
check-branches is vulnerable to OS command injection (CWE-77, CWE-78) due to unsafe construction of Git commands by concatenating untrusted branch names without proper sanitization. The tool spawns shell commands with user-controlled branch name input directly embedded in the command string. An attacker can create a Git branch with shell metacharacters (e.g., ";{echo,hello,world}>/tmp/d") that will be executed when check-branches processes the repository. Since branch names can be controlled remotely via pull requests or by repository collaborators, this vulnerability is network-exploitable in CI/CD contexts. All versions up to 0.0.19 are affected; patches should use proper command parameterization (array-based argument passing) rather than string concatenation.
Affected products
- npm check-branches 0.0.19 and earlier
Timeline
- 2025-09-30: disclosed
- 2025-09-30: advisory: GHSA-9c4g-fp4r-prrv published