Code Execution Vulnerabilities in auto-changelog by CookPete
CVE-2026-12171

8.4HIGH

Key Information:

Vendor

Cookpete

Vendor
CVE Published:
5 October 2026

What is CVE-2026-12171?

The auto-changelog tool prior to version 2.6.1 is susceptible to vulnerabilities that arise when it merges configuration from untrusted repositories. This can lead to the execution of malicious code during workflows that interact with these repositories. Specific options like handlebarsSetup and plugins can load and execute code controlled by attackers, potentially exposing sensitive information and access to workflow secrets. Moreover, the vulnerability allows for git argument injection and can write arbitrary files on the filesystem. With version 2.6.1, the handling of configurations has been improved to treat in-repository settings as untrusted, mitigating these risks unless the --unsafe-config flag is employed.

Affected Version(s)

auto-changelog 0 < 2.6.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d00xy-hash
Jordan Harband (ljharb)
.