OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via a crafted tag name of the target git repository.
https://github.com/jason-rodrigues/CVEX-Record
https://github.com/ucsb-seclab/CVEX-records
https://github.com/advisories/GHSA-9v73-x562-wv5x