simple-git < 3.16.0 - Remote Code Execution
highThe package simple-git is vulnerable to Remote Code Execution in versions before 3.16.0 via the clone(), pull(), push() and listRemote() methods due to improper input sanitization. This is due to an incomplete fix of CVE-2022-25912. WordPress plugins and themes may be using this package, however, they may not be vulner...
- CVSS:
- 8.1
- Affected:
- up to 1.0.3
- Fixed in:
- 1.1.0
- Disclosed:
- Feb 23, 2023