GHSA-q252-mvpj-37m5HighCVSS 7.5
GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that...
🔗 CVE IDs covered (1)
📋 Description
GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that allows malicious repositories to execute commands by substituting crafted filenames into clean/smudge filter commands. Attackers can ship files named with $(command) selected via .gitattributes so checkout or staging runs the command through bash -c as the victim.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-106058
- https://github.com/gitahead/gitahead/issues/661
- https://github.com/gitahead/gitahead
- https://github.com/gitahead/gitahead/blob/v2.7.1/src/git/Filter.cpp#L43-L70
- https://www.vulncheck.com/advisories/gitahead-through-2.7.1-os-command-injection-via-git-filter-filenames
- https://github.com/advisories/GHSA-q252-mvpj-37m5