repomix is vulnerable to Argument Injection
35
Low Risk
Affected versions of this package are vulnerable to command/argument injection in the Git helper: user-controlled repository URLs could be interpreted as command-line options (e.g., starting with -), allowing an attacker to alter the behavior of git ls-remote, git remote add, or git clone and potentially exfiltrate data or tamper with the local repo. The fix inserts the -- end-of-options separator before URL arguments in these invocations so URLs are always treated as positional arguments.
You are affected if you are using a version that falls within the vulnerable range.
repomix is vulnerable to Argument Injection in versions 0.2.4 - 1.3.0.
Upgrade the repomix library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant