Description
The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.
Remediation
References
https://github.com/jkup/pullit/commit/4fec455774ee08f4dce0ef2ef934ffcc37219bfb
https://security.snyk.io/vuln/npm:pullit:20180214
Related Vulnerabilities
CVE-2020-11994 Vulnerability in maven package org.apache.camel:camel-robotframework
CVE-2017-13098 Vulnerability in maven package com.madgag.spongycastle:bctls-jdk15on
CVE-2022-3783 Vulnerability in npm package node-red-dashboard
CVE-2021-23369 Vulnerability in npm package handlebars
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty:jetty-http