Vulnerabilities (CVE)

Filtered by vendor Riceball
Filtered by product Git-commiters
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-59831 1 Riceball 1 Git-commiters 2025-10-16 N/A 8.8 HIGH
git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection vulnerability in git-commiters. This vulnerability manifests with the library's primary exported API: gitCommiters(options, callback) which allows specifying options such as cwd for current working directory and revisionRange as a revision pointer, such as HEAD. However, the library does not sanitize for user input or practice secure process executi ...

Show More