Executive brief
The glob command-line tool is used to find files matching patterns. When the -c/--cmd option is used to execute a command on matched files, the tool unsafely passes filenames directly to the shell. An attacker who can control filenames (e.g., through malicious archives, PR branches, or file uploads) can inject shell commands that execute with the privileges of the user running glob, potentially compromising development environments and CI/CD pipelines.
Technical details
The vulnerability is an OS command injection (CWE-78) in src/bin.mts:277 where the CLI collects glob matches and executes the supplied command using foregroundChild() with shell:true. When glob -c <command> <pattern> is executed, matched filenames are collected into an array and passed directly to a shell interpreter. Attackers can create files with shell metacharacters in their names (e.g., $(malicious_command)) to trigger arbitrary command execution. The vulnerability requires the attacker to control filenames in a directory being processed by glob -c, and is primarily exploitable on POSIX systems due to flexible filename character restrictions. The core glob library API is not affected, only the CLI with the -c/--cmd option. Patches are available in versions 10.5.0, 11.1.0, and 12.0.0; users can upgrade or use the safe --cmd-arg/-g option to pass filenames without shell expansion.
Affected products
- isaacs glob >=10.2.0 <10.5.0 || 11.0.x
Timeline
- 2025-11-17: disclosed: GHSA-5j98-mcp5-4vw2 published
- 2025-11-17: patched: Patches released in versions 10.5.0, 11.1.0, and 12.0.0