Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 1 min 135 bronnen 1 kritiek 11 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-106059

HIGH · 8.8 CVSS Gepubliceerd: CWE-78

Beschrijving

GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.

References