isomorphic-git is vulnerable to Arbitrary File Write
88
High Risk
isomorphic-git writes working-tree files during checkout without verifying that leading path components are not symbolic links. A malicious repository can commit a directory symlink and then, in a later commit or checkout, add a child file under that path, so the write is resolved through the symlink to a location outside the working directory. On host-backed filesystems this allows arbitrary file write, which can be escalated to code execution by targeting files such as ~/.ssh/authorized_keys or the repository .git directory. The fix refuses to traverse symbolic links in the leading path before writing working-tree files.
You are affected if you are using a version that falls within the vulnerable range and your application clones or checks out untrusted repositories on a host-backed filesystem that creates and follows symbolic links.
isomorphic-git is vulnerable to Arbitrary File Write in versions 0.0.1 - 1.38.5.
Upgrade the isomorphic-git library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant