CVE 8.8 HIGH

CVE-2026-11572_CVE-2026-11572

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P

Description

Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exec() method by _cloneWithGit() and fetchRefs() functions. An attacker can execute arbitrary operating system commands as the process user by supplying a specially crafted git repository name.

AI Analysis

Command Injection vulnerability in degit due to improper sanitisation of user input for git shell commands

Basic Information

ID CVE-2026-11572
Source snyk
Published Jun 9, 2026 at 05:00

Affected Product

Vendor Rich Harris
Product degit
Affected Versions n/a degit 0
n/a degit 3.0.0

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Rich Harris
Product degit
Version before 2.8.6, 3.0.0 and before 3.3.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.