Allows an attacker to perform a "Path Traversal" attack to modify files outside the projects directory, potentially allowing for running attacker code on the developer's machine.
Fixed in version 3.2.0
pull and clone commands to verify only expected project files are modified{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-13T20:57:29Z",
"nvd_published_at": "2026-03-13T19:55:13Z",
"severity": "HIGH"
}