jkup/pullit

jkup/pullit

Releases0
Stars182
Display and pull branches from GitHub pull requests

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.