git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in certain PATH situations (most often seen on Windows).
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://github.com/MichaelMure/git-bug/security/advisories/GHSA-m898-h4pm-pqfr | third party advisory |
https://vuln.ryotak.me/advisories/18 | third party advisory |