High severity7.5NVD Advisory· Published Oct 7, 2026
CVE-2026-106058
CVE-2026-106058
Description
GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that allows malicious repositories to execute commands by substituting crafted filenames into clean/smudge filter commands. Attackers can ship files named with $(command) selected via .gitattributes so checkout or staging runs the command through bash -c as the victim.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.