Junglewise Threat Intelligence

CVE-2025-59831: git-commiters command injection vulnerability

CVE-2025-59831 · Severity: low · CVSS 3.1 · Published 2025-09-22

Vendors: npm.

Executive brief

git-commiters is a Node.js library that analyzes Git repositories to generate commit statistics. The library fails to sanitize user input in the revisionRange parameter, allowing attackers to inject arbitrary shell commands that execute with the privileges of the application. An attacker can exploit this to execute malicious commands, create files, or compromise systems running vulnerable versions of the library.

Technical details

The vulnerability is a classic command injection flaw (CWE-77, CWE-78) in the gitCommiters() API function. The root cause is unsanitized concatenation of user-controlled input (the revisionRange parameter) directly into shell commands without using secure process execution APIs that separate arguments from command strings. An attacker can pass a malicious revisionRange value such as "HEAD; touch /tmp/pwn; #" to execute arbitrary commands. The attack requires the attacker to control the options passed to the gitCommiters() function, typically through application input or configuration. The injected commands execute with the same privilege level as the Node.js process. A patch is available in version 0.1.2.

Affected products

  • snowyu git-commiters < 0.1.2

Timeline

  • 2025-09-21: disclosed: Advisory published on GitHub
  • 2025-09-22: advisory: OSV record published
  • 2025-09-22: patched: Fixed in version 0.1.2

References