CVE-2026-75486
Synk Sweater Comb < 3.8.8 Command Injection via .vervet.yaml Branch Name
CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th
Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters.<key>.optic-ci.original branch name field. The expectGitBranch() function in src/lint.ts passes the unsanitized branch name directly into child_process.exec() via an unescaped template literal, enabling arbitrary command execution when the lint command is run against the repository.
| CWE | CWE-78 |
| Vendor | snyk |
| Product | sweater-comb |
| Published | Aug 28, 2026 |
| Last Updated | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for snyk sweater-comb
Be the first to know when new high vulnerabilities affecting snyk sweater-comb are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
snyk / sweater-comb
0 < 3.8.8
References
github.com: https://github.com/snyk/sweater-comb/releases/tag/v3.8.8 github.com: https://github.com/snyk/sweater-comb/pull/743 github.com: https://github.com/snyk/sweater-comb/commit/05a0eec4f2acb9ce6d4814016b475504fc64eab2 vulncheck.com: https://www.vulncheck.com/advisories/synk-sweater-comb-command-injection-via-vervet-yaml-branch-name
Credits
Jashn Wahi VulnCheck