CVE-2024-21531: Git Git-Shallow-Clone

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process variable of the gitShallowClone function.

Affected products

  • Git Git-Shallow-Clone: any version

Published 2024-10-01. Last modified 2026-06-17.