PT-2026-83764 · Klaussilveira · Gitlist

·

CVE-2026-82668

·

Published

2026-08-31

·

Updated

2026-09-01

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions klaussilveira GitList version 2.0.0
Description An OS command injection flaw exists in the Git Command Line component. The issue resides within the getDefaultBranch() function located in the src/SCM/System/Git/CommandLine.php file, which allows a remote attacker to execute arbitrary operating system commands.
Recommendations Upgrade to version 3.0.0-beta. As a temporary mitigation, restrict access to the getDefaultBranch() function.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82668

Affected Products

Gitlist