Description
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.
Remediation
References
https://github.com/jonschlinkert/git-add-remote/blob/master/index.js#L21%2C
https://snyk.io/vuln/SNYK-JS-GITADDREMOTE-564269
Related Vulnerabilities
CVE-2023-26105 Vulnerability in npm package utilities
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom__xmldom
CVE-2020-7729 Vulnerability in npm package grunt
CVE-2020-11057 Vulnerability in maven package org.xwiki.platform:xwiki-platform-dashboard-macro
CVE-2020-9480 Vulnerability in maven package org.apache.spark:spark-network-shuffle_2.11