{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/ci-cd-security/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:synk:sweater_comb:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8,"id":"CVE-2026-75486"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Sweater Comb (\u003c 3.8.8)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","ci-cd-security"],"_cs_type":"advisory","_cs_vendors":["Synk"],"content_html":"\u003cp\u003eSynk Sweater Comb versions prior to 3.8.8 are vulnerable to a command injection flaw originating from the processing of the .vervet.yaml configuration file. The vulnerability exists within the expectGitBranch() function located in src/lint.ts, where user-supplied input from the 'linters.\u0026lt;key\u0026gt;.optic-ci.original' branch name field is concatenated directly into a template literal. This unsanitized string is then passed to the Node.js child_process.exec() function. An attacker who can influence the contents of the repository's configuration file can gain arbitrary OS command execution privileges when a victim executes the linting process. This flaw allows for lateral movement, data exfiltration, or persistence on the developer workstation or CI/CD runner environment where the tool is executed. Defenders should prioritize updating Synk Sweater Comb to version 3.8.8 or higher.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains write access to a repository containing a .vervet.yaml configuration file.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the 'linters.\u0026lt;key\u0026gt;.optic-ci.original' field within the .vervet.yaml file.\u003c/li\u003e\n\u003cli\u003eAttacker injects shell metacharacters and arbitrary commands into the branch name string.\u003c/li\u003e\n\u003cli\u003eVictim triggers the Synk Sweater Comb linting process within the directory.\u003c/li\u003e\n\u003cli\u003eThe expectGitBranch() function reads the malicious branch name from the configuration file.\u003c/li\u003e\n\u003cli\u003eThe unsanitized input is passed directly to the shell via child_process.exec().\u003c/li\u003e\n\u003cli\u003eThe operating system executes the attacker-supplied commands with the privileges of the user running the lint command.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for remote code execution on the target system. This could lead to a full compromise of a developer's workstation or a CI/CD build pipeline, potentially resulting in unauthorized access to source code, secrets, or internal network segments if the runner is improperly scoped.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Synk Sweater Comb to version 3.8.8 or later immediately to patch the command injection vulnerability in src/lint.ts.\u003c/li\u003e\n\u003cli\u003eAudit all repositories using .vervet.yaml for suspicious branch name fields or injected shell syntax (e.g., semicolons, pipe characters, backticks).\u003c/li\u003e\n\u003cli\u003eLimit the permissions of CI/CD runners to ensure that if arbitrary code execution occurs, the attacker cannot reach sensitive internal resources.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-28T21:37:47Z","date_published":"2026-08-28T21:37:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-synk-sweater-comb-injection/","summary":"Synk Sweater Comb before version 3.8.8 contains a command injection vulnerability in the expectGitBranch() function, allowing arbitrary OS command execution via crafted .vervet.yaml configuration files.","title":"Command Injection in Synk Sweater Comb","url":"https://feed.craftedsignal.io/briefs/2026-08-synk-sweater-comb-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Ci-Cd-Security","version":"https://jsonfeed.org/version/1.1"}