AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-59960.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 01, 2026

Disclosure summary

## CI Branch Name OS Command Injection in @argos-ci/core ### Summary `@argos-ci/core@6.2.0` passes attacker-controlled CI branch/ref strings directly into an `execSync()` template literal in `packages/core/src/ci-environment/git.ts:89`. When a CI project has `hasRemoteContentAccess: false`, the Argos upload flow calls `getMergeBaseCommitSha()`, which invokes `gitFetch()` with the unsanitized branch name. Because `execSync()` passes the command string to `/bin/sh -c`, shell metacharacters such as `$()` command substitution are evaluated before `git` runs, enabling an attacker who can influence the branch name (e.g., via a pull request) to execute arbitrary OS commands on the CI runner. CVSS Base Score: 7.5 (High). ### Details The vulnerable sink is in `packages/core/src/ci-environment/git.ts:87-90`: ```ts function gitFetch(input: { ref: string; depth: number; target: string }) { execSync( `git fetch --force --update-head-ok --depth ${input.depth} origin ${input.ref}:${input.target}`, ); } ``` `execSync()` with a template-literal string invokes `/bin/sh -c ""`. The shell expands `$()`, backticks, `;`, and other metacharacters before spawning `git`, so any special characters present i

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-4x45-gxvp-6283

Open original source · Updated Oct 01, 2026

@argos-ci/core: CI Branch Name OS Command Injection

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
npm@argos-ci/core6.2.1

Original records & references

PUBLISHED 2026-09-10T18:34:17-04:00
MODIFIED 2026-10-01T04:56:26-04:00
INGESTED 2026-10-06T11:45:02-04:00