Back

HIGH

Synk Sweater Comb < 3.8.8 Command Injection via .vervet.yaml Branch Name

Published Aug 28, 2026

Description

Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters.<key>.optic-ci.original branch name field. The expectGitBranch() function in src/lint.ts passes the unsanitized branch name directly into child_process.exec() via an unescaped template literal, enabling arbitrary command execution when the lint command is run against the repository.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Aug 28, 2026
Updated Aug 31, 2026
Reserved Aug 17, 2026

CISA Vulnrichment

Updated Aug 31, 2026

NVD

Status Deferred
Modified Sep 8, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Aug 28, 2026
Updated Aug 31, 2026

GitHub

No data