Impact
GitHub Advisory and OSV list get-git-data through 1.3.1 as affected by OS command injection when arguments passed to the package reach shell command construction [S1][S2]. Repository dependency evidence alone does not prove the package is installed in production, called at runtime, receives attacker-controlled input, or that command execution occurred.
How FixVibe covers it
FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve get-git-data versions <=1.3.1, showing the package, file, dependency path and remediation guidance.
Remediation
- Remove get-git-data or replace it with maintained Git metadata tooling that invokes Git with fixed executables and argv arrays rather than shell-built command strings.
- Regenerate the active npm, pnpm, or Yarn lockfile, then rebuild every runtime image, CI image, devcontainer, worker, package-manager cache, or automation host that installs dependencies.
- Review call sites so untrusted request, webhook, job, repository path, branch, commit, remote, or environment data cannot reach Git command arguments.
- Re-run the FixVibe GitHub repo scan after the dependency tree and artifacts are rebuilt.
