CVE-2020-28490: Argument Injection or Modification
(updated )
The package async-git are vulnerable to Command Injection via shell meta-characters (back-ticks). For example, git.reset('a`touch HACKED`b')
References
Detect and mitigate CVE-2020-28490 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →