CVE-2026-106058: Gitahead
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that allows malicious repositories to execute commands by substituting crafted filenames into clean/smudge filter commands. Attackers can ship files named with $(command) selected via .gitattributes so checkout or staging runs the command through bash -c as the victim.
Affected products
- Gitahead Gitahead: up to and including 2.7.1
Published 2026-10-07. Last modified 2026-10-07.