CVE-2026-106059: Gitahead
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.
Affected products
- Gitahead Gitahead: up to and including 2.7.1
Published 2026-10-07. Last modified 2026-10-10.