PT-2026-106024 · Npm · Auto-Changelog
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
auto-changelog versions prior to 2.6.1
Description
The software merges configuration from the target repository, specifically from the
.auto-changelog file and the auto-changelog key in package.json, into its options and honors security-sensitive settings from these untrusted sources. This allows for remote code execution if the tool is run over attacker-controlled content, such as in CI workflows checking out untrusted pull requests or locally on third-party repositories. Specifically, the handlebarsSetup option is passed to require(), and the plugins option loads modules from the repository, both of which can execute arbitrary code with the privileges of the user or CI job. Additionally, appendGitLog and appendGitTag allow git argument injection, which can be used to write arbitrary files via the --output= flag. The output option allows writing influenced content to arbitrary paths, and the template option can trigger outbound requests to attacker-chosen URLs.Recommendations
Update to version 2.6.1 or later.
Exploit
Fix
SSRF
Path traversal
Argument Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Auto-Changelog