contrib/completion/git-prompt.sh in Git before 1.9.3 does...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 20, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.
References