CVE-2026-12171

Source
https://cve.org/CVERecord?id=CVE-2026-12171
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12171.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-12171
Aliases
  • GHSA-xpvr-2hvx-m8q4
Published
2026-10-05T16:25:19Z
Modified
2026-10-06T10:30:38Z
Severity
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
auto-changelog: code execution via untrusted in-repository configuration (handlebarsSetup/plugins), plus argument injection, path traversal, and SSRF
Details

auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed.

Database specific
{
    "cna_assigner":  "harborist",
    "cwe_ids":  [
        "CWE-22",
        "CWE-829",
        "CWE-88",
        "CWE-918",
        "CWE-94"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12171.json"
}
References

Affected packages

Git / github.com/cookpete/auto-changelog

Affected ranges

Type
GIT
Repo
https://github.com/cookpete/auto-changelog
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.6.1"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.0.1
v0.1.0
v0.1.1
v0.2.0
v0.2.1
v0.2.2
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.1.0
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.11.0
v1.12.0
v1.12.1
v1.13.0
v1.14.0
v1.14.1
v1.15.0
v1.16.0
v1.16.1
v1.16.2
v1.16.3
v1.16.4
v1.2.0
v1.2.1
v1.2.2
v1.3.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.5.0
v1.6.0
v1.7.0
v1.7.2
v1.8.0
v1.8.1
v1.9.0
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.2.1
v2.3.0
v2.4.0
v2.5.0
v2.5.1
v2.5.2
v2.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12171.json"