isomorphic-git is vulnerable to Path Traversal
88
High Risk
isomorphic-git's tree parser rejects the reserved .git name and several NTFS 8.3 aliases but does not reject colon-suffixed forms such as .git::$INDEX_ALLOCATION. On Windows NTFS this alias resolves to the real .git directory, so cloning or checking out a crafted repository can write attacker-controlled files into trusted repository metadata such as .git/config and .git/hooks. A later native git command can then read the poisoned configuration and execute an attacker-controlled hook. The fix normalizes entry names on the portion before the first colon so alternate-data-stream aliases of .git are rejected.
You are affected if you are using a version that falls within the vulnerable range and you clone or check out untrusted repositories on Windows with an NTFS filesystem.
isomorphic-git is vulnerable to Path Traversal in versions 0.0.1 - 1.38.6.
Upgrade the isomorphic-git library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant