OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-106059 (CVSS 8.7)

NVD · officialPublished Oct 7, 2026Risk 37/100

GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.

CVSS
8.7
AV:NetworkAC:LowPR:NoneUI:Passive

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source