Arbitrary command execution can be triggered by improperly sanitized SSH URLs in LFS configuration files. This can be triggered by cloning a malicious repository.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2021-0073" }
{ "imports": [ { "path": "github.com/git-lfs/git-lfs/lfsapi", "symbols": [ "Client.NewRequest", "sshAuthClient.Resolve", "sshCache.Resolve", "sshGetLFSExeAndArgs" ] } ] }