GHSA-q252-mvpj-37m5HighCVSS 7.5

GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that...

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that allows malicious repositories to execute commands by substituting crafted filenames into clean/smudge filter commands. Attackers can ship files named with $(command) selected via .gitattributes so checkout or staging runs the command through bash -c as the victim.

🔗 References (6)