Async Git Project maintains a focused asynchronous Git implementation library that, despite limited volume, serves as a foundational component in Rust-based version-control and development tooling. The vendor's disclosures center on its core async_git product and reflect the parsing and state-management complexity inherent to Git protocol implementation. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Async Git Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3190CRITICAL The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag. | Jan 26, 2021 | 9.8 | 32 | NO | NO |
CVE-2020-28490CRITICAL The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb') | Feb 18, 2021 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Async Git Project.
Media articles that mention a CVE ID that affects a product developed by Async Git Project — matched by CVE ID, not by vendor name.