top of page
perceptive_background_267k.jpg

A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerability is the function getDefaultBranch of the file src/SCM/S…

Published:

31 augustus 2026 om 00:00:00

Alert date:

31 augustus 2026 om 12:05:42

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

A critical OS command injection vulnerability (CVE-2026-82668) has been identified in klaussilveira GitList version 2.0.0. The vulnerability exists in the getDefaultBranch function within src/SCM/System/Git/CommandLine.php of the Git Command Line component. An attacker can exploit this flaw remotely to execute arbitrary OS commands. The exploit has been publicly disclosed and is available for use, increasing the risk of active exploitation. A patch has been released and is identified by commit 88cf2866083d5f7c20d9d565c45f828a7ad1516b. Users are strongly advised to upgrade to GitList version 3.0.0-beta to remediate the vulnerability. No workaround is mentioned other than upgrading the affected component.

Technical details

Mitigation steps:

Affected products:

klaussilveira GitList 2.0.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page