CVE-2026-106059: high-severity vulnerability in gitahead
GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7
exploitation probability
—
observed exploitation
nono source reports it
GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
gitahead · gitaheadRelated CVEs — gitahead
In the same product, most dangerous first.