{"id":"CVE-2019-10776","aliases":["GHSA-84cm-v6jp-gjmr"],"url":"https://o3.security/vulnerability/CVE-2019-10776","summary":"OS command injection in git-diff-apply","details":"In \"index.js\" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.","published":"2020-01-07T19:15:10.413Z","modified":"2026-07-08T20:16:03.686496Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"git-diff-apply","fixedVersion":"0.22.2"}],"fix":{"url":"https://github.com/kellyselden/git-diff-apply/commit/106d61d3ae723b4257c2a13e67b95eb40a27e0b5","label":"kellyselden/git-diff-apply@106d61d"},"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-GITDIFFAPPLY-540774%2C"},{"type":"FIX","url":"https://github.com/kellyselden/git-diff-apply/commit/106d61d3ae723b4257c2a13e67b95eb40a27e0b5"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JS-GITDIFFAPPLY-540774"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:16:03.686496Z"}}