{"id":"CVE-2022-25866","aliases":["GHSA-3xpw-vhmv-cw7h","SNYK-PHP-CZPROJECTGITPHP-2421349"],"url":"https://o3.security/vulnerability/CVE-2022-25866","summary":"Command Injection","details":"The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.","published":"2022-04-25T17:10:10.912Z","modified":"2026-08-12T03:51:21.531176904Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"czproject/git-php","fixedVersion":"4.0.3"}],"fix":{"url":"https://github.com/czproject/git-php/commit/5e82d5479da5f16d37a915de4ec55e1ac78de733","label":"czproject/git-php@5e82d54"},"references":[{"type":"WEB","url":"https://github.com/czproject/git-php/releases/tag/v4.0.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25866.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25866"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-PHP-CZPROJECTGITPHP-2421349"},{"type":"FIX","url":"https://github.com/czproject/git-php/commit/5e82d5479da5f16d37a915de4ec55e1ac78de733"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.531176904Z"}}