git-commiters Command Injection Vulnerability

Vulnerability

A command injection vulnerability exists in the git-commiters Node.js module, prior to version 0.1.2. The issue arises in the main exported API, gitCommiters(options, callback), which accepts user-specified options like cwd (current working directory) and revisionRange (a revision pointer such as HEAD). The vulnerability occurs because the library fails to sanitize user input and does not use a secure process execution API to separate commands from their arguments, allowing uncontrolled user input to be concatenated into command execution.

Impact

Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the server running the vulnerable application.

Reproduction

To reproduce this vulnerability, install git-commiters version 0.1.1 or earlier. Then, initialize a new Git directory with commits. In that directory, create a script that requires the git-commiters module and calls the gitCommiters function with a revisionRange option that includes a command to be executed, such as 'touch /tmp/pwn; #'. When the script is run, the injected command will be executed, demonstrating the command injection vulnerability.

Remediation

Users can upgrade to git-commiters version 0.1.2 or later to address this vulnerability.

Added: Sep 25, 2025, 2:20 PM
Updated: Sep 25, 2025, 3:44 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
7.7
relevance
0.5
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.