PT-2025-39374 · Unknown · Git-Commiters

Published

2025-09-21

·

Updated

2025-10-16

·

CVE-2025-59831

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions git-commiters versions prior to 0.1.2
Description git-commiters is a Node.js function module used to provide committers statistics for a git repository. A command injection issue exists due to insufficient input sanitization and insecure process execution. The primary API, gitCommiters(options, callback), is affected, specifically when utilizing the cwd (current working directory) and revisionRange options. User-supplied input is concatenated into command execution without proper separation of commands and arguments, potentially allowing for arbitrary command execution.
Recommendations Update git-commiters to version 0.1.2 or later.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-00173
CVE-2025-59831
GHSA-G38C-WXJF-XRH6

Affected Products

Git-Commiters