CVE-2026-75486EPSS p82.8%
CVE-2026-75486CVE-2026-75486
Description
Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters.<key>.optic-ci.original branch name field. The expectGitBranch() function in src/lint.ts passes the unsanitized branch name directly into child_process.exec() via an unescaped template literal, enabling arbitrary command execution when the lint command is run against the repository.
Scoring
| CVSS | 8.0 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 2.31% probability of exploitation · percentile 82.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-08 |