The git-add-remote npm package through 1.0.0 is affected by the CVE-2020-7630 / GHSA-h9v8-rm3m-5h5f command-injection advisory [S1][S2]. Public advisory records list no patched release [S2][S3].
Impact
Affected versions can become dangerous when application, CI, or developer automation passes attacker-influenced Git remote names into the package [S1][S2]. The practical impact depends on whether the package is installed in a trusted automation environment and whether untrusted input reaches that call path.
Covered by FixVibe
FixVibe's GitHub repository scans flag npm manifests and lockfiles that resolve git-add-remote to the affected range [S2][S4], reported as a high-severity advisory with the package, version and file path.
Remediation
Remove git-add-remote or replace it with maintained Git automation. If Git must be invoked from Node.js, use a fixed executable and argument array such as spawn or execFile, keep remote names, repository URLs, and branch values validated or allowlisted, regenerate the active lockfile, rebuild CI/developer/runtime artifacts that install dependencies, and rerun the repository scan [S2][S3].
