Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitahead
Gitahead gitahead |
|
| Vendors & Products |
Gitahead
Gitahead gitahead |
Wed, 07 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen. | |
| Title | GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T11:59:38.400Z
Reserved: 2026-10-06T14:14:18.038Z
Link: CVE-2026-106059
No data.
Status : Awaiting Analysis
Published: 2026-10-07T12:17:09.100
Modified: 2026-10-07T15:57:20.793
Link: CVE-2026-106059
No data.
OpenCVE Enrichment
Updated: 2026-10-07T13:30:17Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')