CVE-2026-106059 PUBLISHED

GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript

Assigner: VulnCheck
Reserved: 06.10.2026 Published: 07.10.2026 Updated: 07.10.2026

GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor gitahead
Product gitahead
Versions Default: unaffected
  • affected from 0 to 2.7.1 (incl.)

Credits

  • M.J Dhurgesh finder

References

Problem Types

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE