pushgitquickx@1.0.17
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 6:32 AM UTC
OSV ID
MAL-2026-14578
Ecosystem
npm
Summary
The push subcommand of this CLI catches exceptions from git operations and, in the error handler, sends the git error text and JSON-serialized git status output (branch name, tracked and untracked file paths, ahead/behind info) to Google Gemini via the @google/generative-ai SDK using a Google API key hardcoded in the source. The model's response includes a commandsToRun array, and the code iterates that array and executes each string via execSync on the installer's machine with stdio: 'ignore' (for (const cmd of aiResponse.commandsToRun) { execSync(cmd, { stdio: 'ignore' }); }). Because the remote model is conditioned on attacker-influenceable inputs (branch names, file paths, error strings coming from arbitrary repository state) and any command it emits is run without confirmation, allow-listing, or logging, this is a remote-controlled shell-execution surface on the installer's host — running gitquickpush push inside a repo whose contents can steer the model output can result in arbitrary command execution, including destructive git operations or broader host commands. The AI phone-home is also undisclosed in the README, and the git-status payload sent to Google is routed through the author's own hardcoded Gemini API key rather than a caller-configured credential, so the caller does not choose the destination. The same source additionally embeds the author's Google generative-language API key in plaintext, exposing the author's own quota.
Source: amazon-inspector (557f230f5bf78b909b207a6568053a346e32a2fcbd14130a824bd6de8fc7fbf6)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.