isomorphic-git is vulnerable to Path Traversal
53
Medium Risk
isomorphic-git's tree parser validates entry names only against the / and \ path separators and does not reject the reserved name ... Because full paths are assembled incrementally across nested tree objects, a crafted repository can escape the working directory with unbounded depth and write files above it during a single clone or checkout. Overwriting shell startup, configuration, or dot files can escalate to code execution. The fix rejects . and .. (and reserved .git variants) as tree entry names.
You are affected if you are using a version that falls within the vulnerable range and you clone or check out untrusted repositories on a host-backed filesystem.
isomorphic-git is vulnerable to Path Traversal in versions 0.0.1 - 1.38.5.
Upgrade the isomorphic-git library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant