


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerability is the function getDefaultBranch of the file src/SCM/S…
Published:
31 augustus 2026 om 00:00:00
Alert date:
31 augustus 2026 om 12:05:42
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A critical OS command injection vulnerability (CVE-2026-82668) has been identified in klaussilveira GitList version 2.0.0. The vulnerability exists in the getDefaultBranch function within src/SCM/System/Git/CommandLine.php of the Git Command Line component. An attacker can exploit this flaw remotely to execute arbitrary OS commands. The exploit has been publicly disclosed and is available for use, increasing the risk of active exploitation. A patch has been released and is identified by commit 88cf2866083d5f7c20d9d565c45f828a7ad1516b. Users are strongly advised to upgrade to GitList version 3.0.0-beta to remediate the vulnerability. No workaround is mentioned other than upgrading the affected component.
Technical details
Mitigation steps:
Affected products:
klaussilveira GitList 2.0.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82668
https://github.com/klaussilveira/gitlist/
https://github.com/klaussilveira/gitlist/commit/88cf2866083d5f7c20d9d565c45f828a7ad1516b
https://github.com/klaussilveira/gitlist/issues/947
https://github.com/klaussilveira/gitlist/releases/tag/3.0.0-beta
https://vuldb.com/cve/CVE-2026-82668
https://vuldb.com/submit/893866
https://vuldb.com/vuln/397167
https://vuldb.com/vuln/397167/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
