CVE-2019-10776: Git-Diff-Apply Project Git-Diff-Apply

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.

Affected products

Published 2020-01-07. Last modified 2026-06-17.