Description
Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled CI branch or ref values from GITHUB_HEAD_REF or ARGOS_BRANCH can flow through config.branch and getMergeBaseCommitSha() when hasRemoteContentAccess is false. The gitFetch() and gitMergeBase() functions in packages/core/src/ci-environment/git.ts interpolate these values into execSync() command strings executed by /bin/sh -c, so shell metacharacters in a pull-request branch name can execute arbitrary commands with the Argos upload process privileges on the CI runner. Successful exploitation can expose CI secrets, alter build artifacts, or compromise the runner. This issue is fixed in Argos core package version 6.2.1.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An OS command injection flaw exists in Argos JavaScript’s core package that allows an attacker to manipulate CI branch or ref values supplied via GITHUB_HEAD_REF or ARGOS_BRANCH through config.branch and getMergeBaseCommitSha() when hasRemoteContentAccess is false. These values are interpolated into execSync() command strings used by gitFetch() and gitMergeBase() and executed via /bin/sh -c, so shell metacharacters in a pull‑request branch name can trigger arbitrary commands with the Argos upload process privileges on the CI runner. Successful exploitation compromise the entire runner environment. The vulnerability exemplifies CWE‑78, where untrusted input is used to build operating‑system commands without proper sanitization.

Affected Systems

The issue impacts the Argos SDK for JavaScript (repo argos-ci/argos-javascript) when using the core package at versions earlier than 6.2.1. Users running Argos core versions 6.0.x through 6.2.0 are susceptible, while version 6.2.1 and later contain the fix. The vulnerability arises when CI environments set the environment variables GITHUB_HEAD_REF or ARGOS_BRANCH to attacker‐controlled values and the flag hasRemoteContentAccess is false, causing the branch name to flow into command strings.

Risk and Exploitability

The CVSS score the High severity category. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in the C likely attack vector involves an attacker submitting a pull request with a specially crafted branch name that contains shell metacharacters. If the CI job is executed with the Argos upload process, the payload will run with the job runner’s privileges, potentially leaking secrets, corrupting build artifacts, or compromising the entire runner environment.

Generated by OpenCVE AI on September 21, 2026 at 00:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Argos core package to version 6.2.1 or later to remove the vulnerability. The release contains a fix that sanitizes or removes the interpolation of branch names in command strings.
  • Apply whitelist or validation logic for branch names in your CI pipeline to reject or escape shell metacharacters before they reach the Argos upload process. This mitigates the risk if an older Argos version must remain in use temporarily.
  • Re‑evaluate the CI configuration to ensure that GITHUB_HEAD_REF and ARGOS_BRANCH values are sourced from trusted inputs, and consider setting hasRemoteContentAccess to true to prevent the vulnerable code path from being executed.

Generated by OpenCVE AI on September 21, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4x45-gxvp-6283 @argos-ci/core: CI Branch Name OS Command Injection
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Argos-ci
Argos-ci argos-javascript
Vendors & Products Argos-ci
Argos-ci argos-javascript

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled CI branch or ref values from GITHUB_HEAD_REF or ARGOS_BRANCH can flow through config.branch and getMergeBaseCommitSha() when hasRemoteContentAccess is false. The gitFetch() and gitMergeBase() functions in packages/core/src/ci-environment/git.ts interpolate these values into execSync() command strings executed by /bin/sh -c, so shell metacharacters in a pull-request branch name can execute arbitrary commands with the Argos upload process privileges on the CI runner. Successful exploitation can expose CI secrets, alter build artifacts, or compromise the runner. This issue is fixed in Argos core package version 6.2.1.
Title Argos JavaScript: CI Branch Name OS Command Injection in @argos-ci/core
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Argos-ci Argos-javascript
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:06:29.767Z

Reserved: 2026-07-07T18:49:15.608Z

Link: CVE-2026-59960

cve-icon Vulnrichment

Updated: 2026-09-14T19:21:24.519Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T17:17:49.447

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-59960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')