FixVibe

critical

Command Injection in get-git-data (CVE-2020-7619)

get-git-data through 1.3.1 is listed as affected by OS command injection. FixVibe GitHub repo scans flag affected get-git-data versions in npm manifests and lockfiles.

CVE-2020-7619GHSA-wj6h-7chw-x4h2CWE-78

Impact

GitHub Advisory and OSV list get-git-data through 1.3.1 as affected by OS command injection when arguments passed to the package reach shell command construction [S1][S2]. Repository dependency evidence alone does not prove the package is installed in production, called at runtime, receives attacker-controlled input, or that command execution occurred.

How FixVibe covers it

FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve get-git-data versions <=1.3.1, showing the package, file, dependency path and remediation guidance.

Remediation

  • Remove get-git-data or replace it with maintained Git metadata tooling that invokes Git with fixed executables and argv arrays rather than shell-built command strings.
  • Regenerate the active npm, pnpm, or Yarn lockfile, then rebuild every runtime image, CI image, devcontainer, worker, package-manager cache, or automation host that installs dependencies.
  • Review call sites so untrusted request, webhook, job, repository path, branch, commit, remote, or environment data cannot reach Git command arguments.
  • Re-run the FixVibe GitHub repo scan after the dependency tree and artifacts are rebuilt.