GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a url = line in a .lfsconfig file within a repository.
github.com/git-lfs/git-lfs/lfsapi
{
"nvd_published_at": "2017-12-21T06:29:00Z",
"severity": "HIGH",
"github_reviewed_at": "2023-02-08T00:28:40Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-20"
]
}