Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

D00Xy-Hash

#33665of 57,577
8.4Total CVSS
Vulnerabilities · 1
PT-2026-106024
8.4
2026-10-05
Npm · Auto-Changelog · CVE-2026-12171
**Name of the Vulnerable Software and Affected Versions** auto-changelog versions prior to 2.6.1 **Description** The software merges configuration from the target repository, specifically from the `.auto-changelog` file and the `auto-changelog` key in `package.json`, into its options and honors security-sensitive settings from these untrusted sources. This allows for remote code execution if the tool is run over attacker-controlled content, such as in CI workflows checking out untrusted pull requests or locally on third-party repositories. Specifically, the `handlebarsSetup` option is passed to `require()`, and the `plugins` option loads modules from the repository, both of which can execute arbitrary code with the privileges of the user or CI job. Additionally, `appendGitLog` and `appendGitTag` allow git argument injection, which can be used to write arbitrary files via the `--output=` flag. The `output` option allows writing influenced content to arbitrary paths, and the `template` option can trigger outbound requests to attacker-chosen URLs. **Recommendations** Update to version 2.6.1 or later.