@finos/git-proxy
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @finos/git-proxypage 1 of 1
- CVE-2025-54583MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.19.22025-07-30
GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push to remote repositories while bypassing policies and explicit approvals. Since checks and …
- CVE-2025-54584MEDIUMCVSS 5.7EG 5.7✓ Fixed in 1.19.22025-07-30
GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19.1 and below, an attacker can craft a malicious Git packfile to exploit the PACK signature detection in the parsePush.t…
- CVE-2025-54585MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.19.22025-07-30
GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can exploit the way GitProxy handles new branch creation to bypass the approval of prior commits on the parent bra…
- CVE-2025-54586HIGHCVSS 7.1EG 7.1✓ Fixed in 1.19.22025-07-30
GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can inject extra commits into the pack sent to GitHub, commits that aren’t pointed to by any branch. Although …
Check whether @finos/git-proxy is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @finos/git-proxy CVEs against the assets you own.
Start Free Scan →