๐Ÿ” CVE Alert

CVE-2026-12171

HIGH 7.8

auto-changelog: code execution via untrusted in-repository configuration (handlebarsSetup/plugins), plus argument injection, path traversal, and SSRF

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed.

CWE CWE-829 CWE-94 CWE-88 CWE-22 CWE-918
Vendor cookpete
Product auto-changelog
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for cookpete auto-changelog

Be the first to know when new high vulnerabilities affecting cookpete auto-changelog are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

cookpete / auto-changelog
0 < 2.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cookpete/auto-changelog/security/advisories/GHSA-xpvr-2hvx-m8q4 github.com: https://github.com/cookpete/auto-changelog/commit/1d02a48a0a57c69a3cd268aca375d64d50877c1a

Credits

d00xy-hash Jordan Harband (ljharb)