PT-2026-106024 · Npm · Auto-Changelog

·

CVE-2026-12171

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions auto-changelog versions prior to 2.6.1
Description The software merges configuration from the target repository, specifically from the .auto-changelog file and the auto-changelog key in package.json, into its options and honors security-sensitive settings from these untrusted sources. This allows for remote code execution if the tool is run over attacker-controlled content, such as in CI workflows checking out untrusted pull requests or locally on third-party repositories. Specifically, the handlebarsSetup option is passed to require(), and the plugins option loads modules from the repository, both of which can execute arbitrary code with the privileges of the user or CI job. Additionally, appendGitLog and appendGitTag allow git argument injection, which can be used to write arbitrary files via the --output= flag. The output option allows writing influenced content to arbitrary paths, and the template option can trigger outbound requests to attacker-chosen URLs.
Recommendations Update to version 2.6.1 or later.

Exploit

Fix

SSRF

Path traversal

Argument Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-12171
GHSA-XPVR-2HVX-M8Q4

Affected Products

Auto-Changelog