Description
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.
Remediation
References
https://github.com/jonschlinkert/git-add-remote/blob/master/index.js#L21%2C
https://snyk.io/vuln/SNYK-JS-GITADDREMOTE-564269
Related Vulnerabilities
CVE-2020-7762 Vulnerability in npm package jsreport-chrome-pdf
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-debug-jdk15on
CVE-2021-23355 Vulnerability in npm package ps-kill
CVE-2022-25881 Vulnerability in npm package http-cache-semantics
CVE-2023-26486 Vulnerability in maven package org.webjars.bowergithub.vega:vega