CVE-2026-12171
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. –output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new –unsafe-config flag is passed.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cookpete | auto-changelog | 0 < 2.6.1 | affected |
Weaknesses
- CWE-829: CWE-829: Inclusion of Functionality from Untrusted Control Sphere
- CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-88: CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-918: CWE-918: Server-Side Request Forgery (SSRF)
Workarounds
Do not run auto-changelog over untrusted repository content, including CI workflows that check out pull request heads from forks.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: total
Additional References
References
- https://github.com/cookpete/auto-changelog/security/advisories/GHSA-xpvr-2hvx-m8q4
- https://github.com/cookpete/auto-changelog/commit/1d02a48a0a57c69a3cd268aca375d64d50877c1a
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.