GHSA-3g7h-c55x-cx2vHighCVSS 8.8
GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers...
🔗 CVE IDs covered (1)
📋 Description
GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-106059
- https://github.com/gitahead/gitahead/issues/663
- https://github.com/gitahead/gitahead
- https://github.com/gitahead/gitahead/blob/v2.7.1/src/tools/ShowTool.cpp#L40-L48
- https://www.vulncheck.com/advisories/gitahead-through-2.7.1-on-macos-command-injection-via-show-in-finder-applescript
- https://github.com/advisories/GHSA-3g7h-c55x-cx2v