Code Execution Vulnerabilities in auto-changelog by CookPete
CVE-2026-12171
8.4HIGH
What is CVE-2026-12171?
The auto-changelog tool prior to version 2.6.1 is susceptible to vulnerabilities that arise when it merges configuration from untrusted repositories. This can lead to the execution of malicious code during workflows that interact with these repositories. Specific options like handlebarsSetup and plugins can load and execute code controlled by attackers, potentially exposing sensitive information and access to workflow secrets. Moreover, the vulnerability allows for git argument injection and can write arbitrary files on the filesystem. With version 2.6.1, the handling of configurations has been improved to treat in-repository settings as untrusted, mitigating these risks unless the --unsafe-config flag is employed.
Affected Version(s)
auto-changelog 0 < 2.6.1
