CVE-2018-3785
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 4.0%
exploitation probability
4.0%top 10% of all CVEs
observed exploitation
nono source reports it
A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.
Affected products
https://github.com/stevemao · git-dummy-commitReferences
https://hackerone.com/reports/341710