{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/klaussilveira/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:klaussilveira:gitlist:2.0.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-82668"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GitList (2.0.0)"],"_cs_severities":["high"],"_cs_tags":["web-application","rce","os-command-injection"],"_cs_type":"advisory","_cs_vendors":["klaussilveira"],"content_html":"\u003cp\u003eA remote code execution vulnerability (CVE-2026-82668) exists in klaussilveira GitList version 2.0.0. The vulnerability resides within the getDefaultBranch function located in the file src/SCM/System/Git/CommandLine.php. An attacker can exploit this flaw by providing crafted, unsanitized input to the application, which is then concatenated into a system command and executed by the underlying server. Since the vulnerability can be triggered remotely without authentication, it poses a significant risk to any publicly facing GitList installation. Proof-of-concept exploit code has been publicly disclosed, increasing the likelihood of opportunistic exploitation. The vendor has addressed this issue in version 3.0.0-beta via patch 88cf2866083d5f7c20d9d565c45f828a7ad1516b. Users are strongly advised to upgrade their instances immediately to remediate the flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full remote code execution on the host server. This allows an attacker to compromise the confidentiality, integrity, and availability of the repository server, potentially leading to unauthorized data access, further lateral movement within the network, or deployment of additional malware.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all internet-facing GitList 2.0.0 instances to version 3.0.0-beta as indicated in the vendor security advisory. If immediate patching is not feasible, restrict network access to the GitList interface to trusted management networks and audit server logs for unusual process execution patterns stemming from the web server user context.\u003c/p\u003e\n","date_modified":"2026-08-31T11:17:52Z","date_published":"2026-08-31T11:17:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gitlist-rce/","summary":"GitList version 2.0.0 contains an OS command injection vulnerability in the getDefaultBranch function, allowing unauthenticated remote attackers to execute arbitrary system commands.","title":"Remote Code Execution in GitList via OS Command Injection","url":"https://feed.craftedsignal.io/briefs/2026-08-gitlist-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Klaussilveira","version":"https://jsonfeed.org/version/1.1"}