fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.js#63' can be controlled by users without any sanitization to inject arbitrary commands.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| fsa(npm) | 0 | N/A | N/A |
CVSS Metrics