Executive brief
@conventional-changelog/git-client is a Node.js library used to interact with Git repositories for generating conventional changelogs. The getTags() API fails to properly validate or sanitize user-supplied parameters passed to the underlying git log command, allowing attackers to inject arbitrary Git command-line options. This can result in writing or overwriting arbitrary files on the system where the application runs, potentially compromising application configuration files, environment variables, or system files if the process runs with elevated privileges.
Technical details
The vulnerability is an argument injection flaw (CWE-88, CWE-78) in the getTags() API of @conventional-changelog/git-client. The library accepts an optional params array that is passed directly to the git log command without proper validation, sanitization, or use of POSIX double-dash (--) delimiters to terminate option parsing. An attacker can inject Git command-line options such as --output= to write file content to arbitrary locations on disk. While a similar getRawCommits() API implements the secure practice of using --, getTags() does not. Exploitation requires high privileges, user interaction, and high attack complexity; however, it allows arbitrary file write when exploited. The library was patched in version 2.0.0.
Affected products
- conventional-changelog @conventional-changelog/git-client < 2.0.0
Timeline
- 2025-09-22: disclosed
- 2025-09-22: patched: Version 2.0.0 available