CVE-2026-106058: Gitahead

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that allows malicious repositories to execute commands by substituting crafted filenames into clean/smudge filter commands. Attackers can ship files named with $(command) selected via .gitattributes so checkout or staging runs the command through bash -c as the victim.

Affected products

  • Gitahead Gitahead: up to and including 2.7.1

Published 2026-10-07. Last modified 2026-10-07.