The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "1.13.2"
}
],
"source": "CPE_RANGE",
"vendor_product": "async-git_project:async-git",
"cpes": [
"cpe:2.3:a:async-git_project:async-git:*:*:*:*:*:node.js:*:*"
]
},
{
"extracted_events": [
{
"fixed": "1.13.2"
}
],
"source": "DESCRIPTION"
}
]
}