Логотип exploitDog
bind:CVE-2025-59046
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-59046

Количество 3

Количество 3

nvd логотип

CVE-2025-59046

5 месяцев назад

The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branch while it prompts for the branch name on the command-line. It is available as an npm package and can be installed via `npm install -g interactive-git-checkout`. Versions up to and including 1.1.4 of the `interactive-git-checkout` tool are vulnerable to a command injection vulnerability because the software passes the branch name to the `git checkout` command using the Node.js child process module's `exec()` function without proper input validation or sanitization. Commit 8dd832dd302af287a61611f4f85e157cd1c6bb41 fixes the issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4wcm-7hjf-6xw5

5 месяцев назад

interactive-git-checkout has a Command Injection vulnerability

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2025-14328

5 месяцев назад

Уязвимость функции exec() утилиты командной строки interactive-git-checkout, позволяющая нарушителю выполнять произвольные команды

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-59046

The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branch while it prompts for the branch name on the command-line. It is available as an npm package and can be installed via `npm install -g interactive-git-checkout`. Versions up to and including 1.1.4 of the `interactive-git-checkout` tool are vulnerable to a command injection vulnerability because the software passes the branch name to the `git checkout` command using the Node.js child process module's `exec()` function without proper input validation or sanitization. Commit 8dd832dd302af287a61611f4f85e157cd1c6bb41 fixes the issue.

CVSS3: 9.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-4wcm-7hjf-6xw5

interactive-git-checkout has a Command Injection vulnerability

CVSS3: 9.8
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2025-14328

Уязвимость функции exec() утилиты командной строки interactive-git-checkout, позволяющая нарушителю выполнять произвольные команды

CVSS3: 9.8
0%
Низкий
5 месяцев назад

Уязвимостей на страницу