Executive brief
interactive-git-checkout is a popular command-line tool used by developers to quickly switch between git branches. The tool unsafely processes branch names provided by users, allowing an attacker to inject and execute arbitrary shell commands on a developer's machine. An attacker could exploit this to steal credentials, inject malware, modify code, or compromise the entire development environment—particularly dangerous when installed globally on developer workstations.
Technical details
The vulnerability is a classic command injection (CWE-77) flaw where user-supplied input is concatenated directly into a shell command string without sanitization. Specifically, the tool passes the branch name to Node.js child_process.exec() without escaping special characters: exec(`git checkout ${targetBranch}`). Since exec() spawns a shell, shell metacharacters (semicolon, pipe, ampersand, backticks, etc.) in the branch name are interpreted as commands. No authentication or special privileges are required; exploitation occurs during normal interactive use. An attacker can achieve arbitrary code execution in the security context of the user running the tool. A patch has been released that uses proper argument passing (e.g., spawning git with an array of arguments) to prevent shell interpretation.
Affected products
- ninofiliu interactive-git-checkout <=1.1.4
Timeline
- 2025-09-10: disclosed: Advisory published
- 2025-09: patched: Fix committed via git (commit 8dd832d uses argument passing instead of string concatenation)