git-big-picture before 1.0.0 mishandles ' characters in a branch name, leading to code execution.
"https://github.com/pypa/advisory-database/blob/main/vulns/git-big-picture/PYSEC-2021-15.yaml"