"The concern is that a rogue submodule can trick the Git into running code it shouldn’t outside the context of the repository. 'This allowed an adversary to exfiltrate data, pull down a web shell, plant a cryptominer or just totally own the machine...'" #security
https://threatpost.com/bug-in-git-opens-developer-systems-up-to-attack/132395/