mediumVulnerability

GHSA-5g3j-89fr-r2vp

## Summary `skilleton` versions prior to `0.3.1` include security-related weaknesses in repository normalization and path handling logic. Version `0.3.1` contains fixes and additional test coverage for these issues. ## Affected Versions `<0.3.1` ## Patched Versions `>=0.3.1` ## Impact In affected versions, crafted input could trigger unsafe or inefficient behavior in repository/path processing code paths. `0.3.1` mitigates this by: - replacing vulnerable parsing behavior with deterministic logic, - validating subpaths earlier before allocating git worktree resources, - adding stricter and broader regression tests around these flows. ## Severity Low to Moderate (project-maintainer assessed) ## Mitigation Upgrade to `0.3.1` or later. ## Workarounds No complete workaround is recommended other than upgrading. ## References - Branch: [`fix/security-code-scanning-alerts`](https://github.com/Fcmam5/skilleton/pull/9) - Commits: - [fix(security): harden git arg handling and path validation](https://github.com/Fcmam5/skilleton/pull/9/changes/42bc280ad675bfaa7b1bbc192330fb582bb28172) - [fix(security): use while loop in normalizeRepoUrl instead of regex](https://github.com/Fcmam5/skilleton/pull/9/changes/6613160803ec8655efee9a270eeaa767ad22da8b) - Security Policy: [SECURITY.md](https://github.com/Fcmam5/skilleton/blob/master/SECURITY.md) ## Credits Detected through automated code scanning and remediated by project maintainers.

Properties

ghsa_id
GHSA-5g3j-89fr-r2vp
severity
medium
summary
skilleton has improper input handling in repository/path processing
cve_id
GHSA-5g3j-89fr-r2vp
is_ghsa_only
true
ghsa_published
2026-04-08T00:07:36Z
source_url
https://github.com/advisories/GHSA-5g3j-89fr-r2vp
ghsa_updated
2026-04-08T00:07:38Z

Related Entities (7)

VULNERABLE_TO (1)

[Software]npm/skilleton

HAS_WEAKNESS (4)

[Weakness]Inefficient Regular Expression Complexity
[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
[Weakness]Uncontrolled Resource Consumption
[Weakness]Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]npm/skilleton

Explore deeper with Ninja Signal's threat intelligence graph