CVE-2022-24440General(cocoapods / cocoapods-downloader)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cocoapods-downloader

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
cocoapods-downloader

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-04: 1Technical Details · 2026-05-04: 105-04
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • SecureChap@SecureChap
    General

    Nineteen years separate the first cataloged package manager path traversal (CVE-2007-0469) from this year's rediscovery (CVE-2026-34591, CVE-2026-35206). Same bug class. Same archive-extraction primitive. Different ecosystem. A new survey by Nesbitt catalogs a dozen CWE patterns that hit npm, PyPI, RubyGems, Composer, Cargo, Go, Helm, NuGet, and Conda over and over. A few standouts: Argument injection into VCS tools - six separate CVEs in one tool alone across git, hg, and Perforce wrappers (CVE-2021-29472, CVE-2022-36069, CVE-2021-43809, CVE-2023-5752, CVE-2022-24440, plus one more). Integrity checks that fail open: CVE-2016-1252 (clearsigned parser accepted unsigned content), CVE-2022-31156 (sig check silently skipped on error), CVE-2022-46176 (missing SSH host key on git index clones). Dependency confusion was already CVE-2013-0334 - eight years before its 2021 fame. Terminal escape sequences in package metadata: at least nine CVEs across four ecosystems. CocoaPods CVE-2024-38368: an orphaned admin API was left in place for ten years, until a researcher used it to claim 1,800 packages. The thesis: knowledge doesn't transfer between projects. Every ecosystem rediscovers the same dozen bugs from scratch. http://nesbitt.io/2026/05/04/package-manager-cwes.html

    Post summary

    A survey summarizes repeated package‑manager vulnerabilities across ecosystems, citing many CVEs and their bug classes but providing no PoC, exploit, or patch details.

    0000043
    44 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appcocoapodscocoapods-downloader---
Appcocoapodscocoapods-downloader1.6.2--

Explore more