GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfsconfig file within a repository.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-17831.json"