All versions of package git-promise is vulnerable to Command Injection due to an inappropriate fix of a prior vulnerability in this package. Note: Please note that the vulnerability will not be fixed. The README file was updated with a warning regarding this issue.
@lirantal for discovering this vulnerability.
{
"cwe_ids": [
"CWE-77",
"CWE-88"
],
"github_reviewed": true,
"github_reviewed_at": "2022-06-17T00:56:05Z",
"nvd_published_at": "2022-06-10T20:15:00Z",
"severity": "HIGH"
}