Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to auto-changelog 2.6.1 or later. Options that load code, inject git arguments, write outside the repository, or fetch URLs must now be passed on the command line; `--unsafe-config` restores the old behavior for fully trusted repositories only.
Workaround
Do not run auto-changelog over untrusted repository content, including CI workflows that check out pull request heads from forks.
Mon, 05 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed. | |
| Title | auto-changelog: code execution via untrusted in-repository configuration (handlebarsSetup/plugins), plus argument injection, path traversal, and SSRF | |
| Weaknesses | CWE-22 CWE-829 CWE-88 CWE-918 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: harborist
Published:
Updated: 2026-10-05T16:25:19.098Z
Reserved: 2026-06-12T21:15:49.095Z
Link: CVE-2026-12171
No data.
Status : Received
Published: 2026-10-05T17:17:14.510
Modified: 2026-10-05T17:17:14.510
Link: CVE-2026-12171
No data.
OpenCVE Enrichment
Updated: 2026-10-05T17:30:11Z