FixVibe

high

OS Command Injection in git-add-remote (CVE-2020-7630)

The git-add-remote npm package is vulnerable to OS command injection. Attackers can execute arbitrary commands on the host system by providing malicious input to the package's functions, which fail to properly sanitize arguments before passing them to the system shell.

CVE-2020-7630GHSA-H9V8-RM3M-5H5FCWE-78

The git-add-remote npm package through 1.0.0 is affected by the CVE-2020-7630 / GHSA-h9v8-rm3m-5h5f command-injection advisory [S1][S2]. Public advisory records list no patched release [S2][S3].

Impact

Affected versions can become dangerous when application, CI, or developer automation passes attacker-influenced Git remote names into the package [S1][S2]. The practical impact depends on whether the package is installed in a trusted automation environment and whether untrusted input reaches that call path.

Covered by FixVibe

FixVibe's GitHub repository scans flag npm manifests and lockfiles that resolve git-add-remote to the affected range [S2][S4], reported as a high-severity advisory with the package, version and file path.

Remediation

Remove git-add-remote or replace it with maintained Git automation. If Git must be invoked from Node.js, use a fixed executable and argument array such as spawn or execFile, keep remote names, repository URLs, and branch values validated or allowlisted, regenerate the active lockfile, rebuild CI/developer/runtime artifacts that install dependencies, and rerun the repository scan [S2][S3].