Command Injection Vulnerability in GitAhead for macOS
CVE-2026-106059
8.7HIGH
What is CVE-2026-106059?
GitAhead, a Git GUI client for macOS, is affected by a security flaw that allows malicious users to execute arbitrary shell commands. This vulnerability arises when an attacker crafts a specially designed repository filename containing a shell script embedded within a double quote. When a victim user selects 'Show in Finder', the application unwittingly executes the attacker's script as the current user, potentially compromising the user's system. Users are strongly advised to update to the latest version to mitigate this risk.
Affected Version(s)
gitahead 0 <= 2.7.1
