Vulnerability Description
Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exec() method by _cloneWithGit() and fetchRefs() functions. An attacker can execute arbitrary operating system commands as the process user by supplying a specially crafted git repository name.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://gist.github.com/badp3te/cf22a939eedbd3d8ade9123827d61639
- https://github.com/Rich-Harris/degit/commit/4ac99e4a4c3f53ca3b5c997bcd7542742ad0
- https://github.com/Rich-Harris/degit/commit/d55bfd7cea79c0b387f69ec8477b6c34abf9
- https://security.snyk.io/vuln/SNYK-JS-DEGIT-17116207
- https://gist.github.com/badp3te/cf22a939eedbd3d8ade9123827d61639
FAQ
What is CVE-2026-11572?
CVE-2026-11572 is a vulnerability with a CVSS score of 8.8 (HIGH). Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exec...
How severe is CVE-2026-11572?
CVE-2026-11572 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11572?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.