Arbitrary command execution can be triggered by improperly sanitized SSH URLs in LFS configuration files. This can be triggered by cloning a malicious repository.
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2021-0073"
}