Command Injection in node-gitlog - CVE-2021-26541
Published: February 16, 2021
node-gitlog
Dom Harrington
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to improper input validation in the "gitlog" function in "src/index.ts". A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary commands on the target system.