Executive brief
degit is a tool used by developers to quickly download and clone project templates from Git repositories. A security flaw allows an attacker to execute malicious commands on a user's computer if the user is tricked into attempting to download a specially crafted repository name. This could lead to a full system compromise, data theft, or the installation of malware on the developer's workstation.
Technical details
The degit package is vulnerable to OS command injection because it fails to properly sanitize user-supplied input before passing it to git shell commands. Specifically, the `_cloneWithGit()` and `fetchRefs()` functions use the `exec()` method to invoke shell commands directly. An attacker can exploit this by providing a maliciously crafted git repository name containing shell metacharacters. If a user or automated process attempts to fetch such a repository, the injected commands will execute with the privileges of the process running degit. The vulnerability is addressed in versions 2.8.6 and 3.3.1.
Affected products
- Rich-Harris degit < 2.8.6, >= 3.0.0 < 3.3.1
Timeline
- 2026-05-20: patched: Fixes committed to repository
- 2026-06-09: disclosed: Initial advisory publication
- 2026-07-30: advisory: GitHub Advisory reviewed and updated