Impact
The vulnerability permits execution of arbitrary shell commands when a user selects the "Show in Finder" action in GitAhead on macOS. By crafting a repository file name that contains a double quote followed by a shell command, the embedded AppleScript is injected. When the command is executed it runs with the privileges of the victim user, allowing full compromise of the local machine. This is a classic command injection flaw classified as CWE‑78.
Affected Systems
GitAhead versions up to 2.7.1 on macOS are affected. The bug exists in the ShowTool.cpp component where repository paths are interpolated unescaped into AppleScript.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the lack of an EPSS rating means no exploitation probability has been quantified, but the nature of the flaw suggests it could be leveraged by legitimate or malicious insiders or attackers with access to the client. The vulnerability is not listed in CISA KEV at present, though its potential impact warrants prompt mitigation. The attack vector requires that the affected user invokes the Show in Finder function on a repository containing an attacker‑crafted filename, implying that exploit requires local or authenticated access to the target machine.
OpenCVE Enrichment