Vendor
A command injection vulnerability in libgit2 versions v0.27.0 through v1.9.0 allows remote code execution during recursive repository clones when using the libssh2 SSH backend.