Security vulnerability affects the git package. A malicious third-party can give a crafted "ssh://.
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2025/CLEANSTART-2025-KP82477.json"