CVE-2026-106059
EUVD-2026-9430707.10.2026, 12:17
GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.
Awaiting analysis
This vulnerability is currently awaiting analysis.