-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| workspace-tools | npm | < 0.18.4 | 0.18.4 |
The commit diff shows both functions were patched by adding '--' argument separation in git fetch calls. This indicates they previously allowed injecting flags via user-controlled parameters (remote/remoteBranch). The CVE description explicitly implicates fetchRemoteBranch, while fetchRemote shares the same vulnerable pattern. The Snyk PoC demonstrates exploitation via parameter manipulation, and the fix confirms both were attack vectors.
Ongoing coverage of React2Shell