git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to "cd " and "git clone " commands in the library.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSquareup Git Fastclone
APPSquareup< 1.0.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2015-8968HIGH8.8same product
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can inst...
CVE-2018-1000844CRITICAL9.1PL ✓same vendor
XXE w Squareup Retrofit umożliwiające odczyt plików i SSRF
CVE-2026-45799HIGH7.5PL ✓same vendor
Wire (gRPC/protobuf): brak walidacji długości pola powoduje crash usługi
CVE-2018-1000850HIGH7.5same vendor
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vul...
CVE-2023-0833MEDIUM4.7same vendor
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information d...