{"id":"CVE-2021-3190","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-3190","summary":"OS Command Injection in async-git","details":"The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. Ensure to sanitize untrusted user input before passing it to one of the vulnerable functions as a workaround or update async-git to version 1.13.1.","published":"2021-01-29T18:14:00Z","modified":"2023-11-08T04:05:51.640137Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"async-git","fixedVersion":"1.13.2"}],"fix":{"url":"https://github.com/omrilotan/async-git/pull/13","label":"omrilotan/async-git#13"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3190"},{"type":"WEB","url":"https://github.com/omrilotan/async-git/pull/13"},{"type":"WEB","url":"https://github.com/omrilotan/async-git/pull/13/commits/611823bd97dd41e9e8127c38066868ff9dcfa57a"},{"type":"WEB","url":"https://github.com/omrilotan/async-git/pull/13/commits/a5f45f58941006c4cc1699609383b533d9b92c6a"},{"type":"WEB","url":"https://github.com/omrilotan/async-git/pull/14"},{"type":"WEB","url":"https://advisory.checkmarx.net/advisory/CX-2021-4772"},{"type":"PACKAGE","url":"https://github.com/omrilotan/async-git"},{"type":"WEB","url":"https://www.npmjs.com/package/async-git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:05:51.640137Z"}}