CVE-2026-12171

Summary

auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. –output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new –unsafe-config flag is passed.

Affected Software

VendorProductVersion RangeStatus
cookpeteauto-changelog0 < 2.6.1affected

Weaknesses

  • CWE-829: CWE-829: Inclusion of Functionality from Untrusted Control Sphere
  • CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
  • CWE-88: CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
  • CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-918: CWE-918: Server-Side Request Forgery (SSRF)

Workarounds

Do not run auto-changelog over untrusted repository content, including CI workflows that check out pull request heads from forks.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: total

Additional References

References