THREAT OPS › Threat News › [GHSA] GHSA-4x45-gxvp-6283 (high) — @argos-ci/core: CI Branch Name OS Command Injection
[GHSA] GHSA-4x45-gxvp-6283 (high) — @argos-ci/core: CI Branch Name OS Command Injection
GHSA-4x45-gxvp-6283 Severity: high CVE: CVE-2026-59960
@argos-ci/core: CI Branch Name OS Command Injection
## CI Branch Name OS Command Injection in @argos-ci/core
### Summary
`@argos-ci/core@6.2.0` passes attacker-controlled CI branch/ref strings directly into an `execSync()` template literal in `packages/core/src/ci-environment/git.ts:89`. When a CI project has `hasRemoteContentAccess: false
MITRE ATT&CK techniques
Indicators of compromise
- aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaasha1
- 0123456789abcdef0123456789abcdef01234567sha1
- CVE-2026-59960cve
- http://127.0.0.1:7777/v2/url
- http://127.0.0.1:{MOCK_PORT}/v2/url
- poc@test.localemail
Original source: https://github.com/advisories/GHSA-4x45-gxvp-6283