CVE-2026-12171
Received Received - Intake

Command Injection in auto-changelog

Vulnerability report for CVE-2026-12171, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: harborist

Description

auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cookpete auto-changelog 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-12171 is a Remote Code Execution (RCE) vulnerability in the auto-changelog npm package affecting versions 2.6.0 and below. The tool merges configuration from untrusted repository files like .auto-changelog or package.json into its options. Attackers can exploit this by committing malicious files and referencing them in the repository's configuration to execute arbitrary code via Node.js's require() function.

Detection Guidance

Check if auto-changelog versions 2.6.0 or below are installed using npm list auto-changelog or npm ls auto-changelog. Inspect repository configurations for .auto-changelog or package.json for suspicious options like handlebarsSetup, plugins, output, or template.

Impact Analysis

This vulnerability allows attackers to execute arbitrary code with the privileges of the user or CI job running auto-changelog. It can lead to secret exfiltration, malicious releases, arbitrary file writes, and Server-Side Request Forgery (SSRF). The attack requires no user interaction beyond running the tool on an untrusted repository.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Unauthorized code execution may result in data breaches, non-compliance with data handling regulations, and potential legal consequences.

Mitigation Strategies

Upgrade auto-changelog to version 2.7.0 or later. Avoid running auto-changelog on untrusted repositories in CI environments. Do not use the --unsafe-config flag unless absolutely necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12171. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart