QID 982830
QID 982830: Nodejs (npm) Security Update for @graphql-tools/git-loader (GHSA-vhhw-xjvf-wprr)
This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vhhw-xjvf-wprr for updates pertaining to this vulnerability.
Vendor References
- GHSA-vhhw-xjvf-wprr -
github.com/advisories/GHSA-vhhw-xjvf-wprr
CVEs related to QID 982830
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vhhw-xjvf-wprr | @graphql-tools/git-loader |
|