{"id":"CVE-2026-12171","title":"auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source","summary":"auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-22","CWE-88","CWE-94","CWE-829","CWE-918"],"vendor":"cookpete","product":"auto-changelog","affected":["auto-changelog < 2.6.1"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T17:17:14.510","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12171","references":[{"url":"https://github.com/cookpete/auto-changelog/commit/1d02a48a0a57c69a3cd268aca375d64d50877c1a","label":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"},{"url":"https://github.com/cookpete/auto-changelog/security/advisories/GHSA-xpvr-2hvx-m8q4","label":"7ffcee3d-2c14-4c3e-b844-86c6a321a158"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-05T17:27:45.054Z","slug":"CVE-2026-12171","body":"## Overview\n\nauto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}