THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4x45-gxvp-6283 (high) — @argos-ci/core: CI Branch Name OS Command Injection

[GHSA] GHSA-4x45-gxvp-6283 (high) — @argos-ci/core: CI Branch Name OS Command Injection

highgithub_advisoriesPublished 2026-09-10

GHSA-4x45-gxvp-6283 Severity: high CVE: CVE-2026-59960

@argos-ci/core: CI Branch Name OS Command Injection

## CI Branch Name OS Command Injection in @argos-ci/core

### Summary

`@argos-ci/core@6.2.0` passes attacker-controlled CI branch/ref strings directly into an `execSync()` template literal in `packages/core/src/ci-environment/git.ts:89`. When a CI project has `hasRemoteContentAccess: false

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4x45-gxvp-6283