{"id":"CVE-2026-75486","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-75486","summary":"Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by…","details":"Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters.<key>.optic-ci.original branch name field. The expectGitBranch() function in src/lint.ts passes the unsanitized branch name directly into child_process.exec() via an unescaped template literal, enabling arbitrary command execution when the lint command is run against the repository.","published":"2026-08-28T20:19:54.027","modified":"2026-08-28T20:19:54.027","cvss":{"score":8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/snyk/sweater-comb/commit/05a0eec4f2acb9ce6d4814016b475504fc64eab2","label":"snyk/sweater-comb@05a0eec"},"references":[{"type":"WEB","url":"https://github.com/snyk/sweater-comb/commit/05a0eec4f2acb9ce6d4814016b475504fc64eab2"},{"type":"WEB","url":"https://github.com/snyk/sweater-comb/pull/743"},{"type":"WEB","url":"https://github.com/snyk/sweater-comb/releases/tag/v3.8.8"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/synk-sweater-comb-command-injection-via-vervet-yaml-branch-name"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T20:19:54.027"}}