Description
GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.
Published: 2026-10-07
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution via Command Injection
Action: Apply Patches
AI Analysis

Impact

The vulnerability permits execution of arbitrary shell commands when a user selects the "Show in Finder" action in GitAhead on macOS. By crafting a repository file name that contains a double quote followed by a shell command, the embedded AppleScript is injected. When the command is executed it runs with the privileges of the victim user, allowing full compromise of the local machine. This is a classic command injection flaw classified as CWE‑78.

Affected Systems

GitAhead versions up to 2.7.1 on macOS are affected. The bug exists in the ShowTool.cpp component where repository paths are interpolated unescaped into AppleScript.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and the lack of an EPSS rating means no exploitation probability has been quantified, but the nature of the flaw suggests it could be leveraged by legitimate or malicious insiders or attackers with access to the client. The vulnerability is not listed in CISA KEV at present, though its potential impact warrants prompt mitigation. The attack vector requires that the affected user invokes the Show in Finder function on a repository containing an attacker‑crafted filename, implying that exploit requires local or authenticated access to the target machine.

Generated by OpenCVE AI on October 7, 2026 at 13:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GitAhead to the latest version that resolves the command injection flaw, if a patch is available.
  • If updating is not immediately possible, avoid using the "Show in Finder" feature with repositories that may contain untrusted file names.
  • As an interim measure, modify the ShowTool.cpp source to escape or sanitize repository paths before embedding them into AppleScript, or disable the feature entirely until a patched release is issued.

Generated by OpenCVE AI on October 7, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Gitahead
Gitahead gitahead
Vendors & Products Gitahead
Gitahead gitahead

Wed, 07 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Description GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.
Title GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Gitahead Gitahead
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-07T11:59:38.400Z

Reserved: 2026-10-06T14:14:18.038Z

Link: CVE-2026-106059

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T12:17:09.100

Modified: 2026-10-07T12:17:09.100

Link: CVE-2026-106059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T13:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')