VYPR

Argos Javascript

by Argos Ci

CVEs (1)

  • CVE-2026-59960higSep 10, 2026
    risk 0.38cvss epss

    ## CI Branch Name OS Command Injection in @argos-ci/core ### Summary `@argos-ci/[email protected]` passes attacker-controlled CI branch/ref strings directly into an `execSync()` template literal in `packages/core/src/ci-environment/git.ts:89`. When a CI project has…