GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitahead
Gitahead gitahead |
|
| Vendors & Products |
Gitahead
Gitahead gitahead |
Wed, 07 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen. | |
| Title | GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T11:59:38.400Z
Reserved: 2026-10-06T14:14:18.038Z
Link: CVE-2026-106059
No data.
Status : Received
Published: 2026-10-07T12:17:09.100
Modified: 2026-10-07T12:17:09.100
Link: CVE-2026-106059
No data.
OpenCVE Enrichment
Updated: 2026-10-07T13:30:17Z
Weaknesses