OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-12171

HIGH · CVSS 7.8 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The auto-changelog tool prior to version 2.6.1 is vulnerable to code execution and arbitrary file manipulation due to its handling of configuration from untrusted repositories, allowing attackers to execute malicious code with the privileges of the user or CI job. This vulnerability can expose sensitive workflow secrets and facilitate unauthorized actions, making it critical for developers and CI/CD pipeline operators to prioritize upgrading to version 2.6.1 or later to mitigate these risks. Organizations that utilize auto-changelog in environments where untrusted code is processed should take immediate action to address this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-12171
Severity
HIGH
CVSS
7.8
EPSS
0.22%

Original NVD Description

auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed.