CVE-2026-106058
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Oct 07, 2026
Vendor
unknown
Description
GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that allows malicious repositories to execute commands by substituting crafted filenames into clean/smudge filter commands. Attackers can ship files named with $(command) selected via .gitattributes so checkout or staging runs the command through bash -c as the victim.