{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "2.6.1"
              }
            ],
            "source": "AFFECTED_FIELD"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3c33a5b48ee27bc7141c9c7b6471a9f24af6b119"
            }
          ],
          "repo": "https://github.com/cookpete/auto-changelog",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-xpvr-2hvx-m8q4"
  ],
  "database_specific": {
    "cna_assigner": "harborist",
    "cwe_ids": [
      "CWE-22",
      "CWE-829",
      "CWE-88",
      "CWE-918",
      "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12171.json"
  },
  "details": "auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed.",
  "id": "CVE-2026-12171",
  "modified": "2026-10-06T10:30:38.828871214Z",
  "published": "2026-10-05T16:25:19.098Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12171.json"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/cookpete/auto-changelog"
    },
    {
      "type": "FIX",
      "url": "https://github.com/cookpete/auto-changelog/commit/1d02a48a0a57c69a3cd268aca375d64d50877c1a"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/cookpete/auto-changelog/security/advisories/GHSA-xpvr-2hvx-m8q4"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12171"
    },
    {
      "type": "WEB",
      "url": "https://www.npmjs.com/"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "auto-changelog: code execution via untrusted in-repository configuration (handlebarsSetup/plugins), plus argument injection, path traversal, and SSRF"
}