Sceawere

Vulnerability Detail

CVE-2026-12171UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

auto-changelog Configuration Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
2h ago
Vendor
cookpete
Product
auto-changelog
Attack Type
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-10-05T17:17:14.510Z",
  "pubdate": "2026-10-05T17:17:14.510Z",
  "executiveSummary": "The auto-changelog package prior to version 2.6.1 is susceptible to multiple security vulnerabilities stemming from the insecure handling of configuration files within target repositories. Specifically, the tool merges settings from .auto-changelog or the auto-changelog key in package.json into its execution options without sufficient sanitization or trust boundaries. This design flaw allows an attacker who controls the repository content—such as in a malicious pull request or a compromised project—to achieve Remote Code Execution (RCE), arbitrary file write, and sensitive information exfiltration.\nThe primary risk arises when auto-changelog is executed in environments where untrusted code is processed, such as CI/CD pipelines or local analysis of third-party repositories. Because the tool honors security-sensitive directives like handlebarsSetup and plugins, an attacker can force the application to execute arbitrary code or load malicious modules with the privileges of the system running the utility. Consequently, an attacker could compromise secrets, environment variables, or other sensitive data residing within the CI/CD environment. The vulnerability is effectively mitigated in version 2.6.1 by treating in-repository configurations as untrusted, requiring explicit user consent via the --unsafe-config flag to process potentially dangerous directives.",
  "technicalDetails": "The core vulnerability lies in the improper processing of untrusted, user-provided configuration files by auto-changelog before version 2.6.1. When the tool runs, it automatically discovers and merges configuration settings defined within the target repository, specifically looking for a .auto-changelog file or an auto-changelog field within package.json. These configuration sources are treated as trusted input, which the application integrates directly into its internal options object. This architectural decision creates a direct path for various injection attacks, as several key configuration options are passed directly to sensitive system interfaces.\nOne critical attack vector involves the 'handlebarsSetup' option. The application passes the value associated with this key directly into the Node.js 'require()' function. By crafting a malicious repository containing a specially formatted .auto-changelog file, an attacker can point this option to an arbitrary local file or malicious script. When auto-changelog executes, the 'require()' call triggers the execution of that script with the same privilege level as the invoking process. This allows for trivial Remote Code Execution (RCE) in CI/CD pipelines or local developer environments. A similar attack vector exists through the 'plugins' option, which facilitates the loading of arbitrary, attacker-controlled modules from the repository filesystem.\nBeyond code execution, the tool exposes parameters that facilitate secondary attacks. Specifically, the 'appendGitLog' and 'appendGitTag' options are susceptible to git argument injection. By supplying malicious arguments (e.g., --output=), an attacker can overwrite arbitrary files on the filesystem with the output of the tool. Furthermore, the 'output' option allows for writing controlled data to arbitrary file paths, potentially allowing an attacker to overwrite critical system configuration files or binary assets. Finally, the 'template' option can be manipulated to initiate outbound network requests to attacker-controlled URLs, which could be used for SSRF (Server-Side Request Forgery) or exfiltration of sensitive configuration values.\nThe exploitation flow is straightforward: 1) An attacker contributes a malicious configuration file to a repository. 2) A victim or an automated CI pipeline triggers auto-changelog against the repository. 3) The tool parses the malicious config, honoring the injection-prone keys. 4) The tool executes the attacker-defined code or performs unauthorized file operations during its normal execution flow, successfully compromising the host system without requiring any external dependencies to be installed."
}
CVE-2026-12171: auto-changelog Configuration Injection Vulnerability (HIGH Severity, CVSS: 7.8) | Sceawere