CVE-2026-49987: Yamadashy Repomix

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly to git fetch and git checkout without validation or --end-of-options, allowing --upload-pack or other Git option injection that bypasses validateGitUrl() dangerous parameter checks and can execute commands through local or SSH-style transports. This issue is fixed in version 1.14.1.

Affected products

  • Yamadashy Repomix: before 1.14.1 (fixed in 1.14.1)

Published 2026-07-15. Last modified 2026-08-18.