CVE-2026-12171: CWE-829: Inclusion of Functionality from Untrusted Control Sphere in cookpete auto-changelog
Description
auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed.
CVSS v4.0
Score 8.4high
Affected software
cookpete
auto-changelog
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in auto-changelog before version 2.6.1 arises because it merges configuration from the target repository (such as the .auto-changelog file and the auto-changelog key in package.json) into its runtime options without sufficient trust validation. This includes honoring security-sensitive options like handlebarsSetup, which is passed to require(), enabling execution of arbitrary code from attacker-controlled repositories. Additional attack vectors include loading malicious plugins, git argument injection allowing arbitrary file writes, and making outbound requests to attacker-controlled URLs. The issue is mitigated in version 2.6.1 by treating in-repository configuration as untrusted and refusing to run when these options are set unless the user explicitly opts in with the --unsafe-config flag.
Potential Impact
An attacker who controls repository content can execute arbitrary code with the privileges of the user or CI job running auto-changelog. This includes access to workflow secrets and the ability to write arbitrary files or make outbound network requests. The vulnerability affects scenarios such as running auto-changelog on untrusted pull request heads or third-party repositories without installed dependencies.
Mitigation Recommendations
Upgrade to auto-changelog version 2.6.1 or later, which treats in-repository configuration as untrusted and refuses to run when security-sensitive options are set unless explicitly overridden with the --unsafe-config flag. Avoid running auto-changelog on untrusted repository content without this upgrade. Patch status is confirmed by the vendor's release of version 2.6.1.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- harborist
- Date Reserved
- 2026-06-12T21:15:49.095Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac3d4fd2cdf04f6561c5106
Added to database: 10/05/2026, 16:49:01 UTC
Last enriched: 10/05/2026, 17:03:17 UTC
Last updated: 10/05/2026, 19:34:03 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.