All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.
Credit to @lirantal for discovering this vulnerability.
{
"cwe_ids": [
"CWE-77",
"CWE-88"
],
"github_reviewed": true,
"github_reviewed_at": "2022-07-06T19:51:34Z",
"nvd_published_at": "2022-07-01T20:15:00Z",
"severity": "HIGH"
}