HIGH
snyk
CVE published 2026-08-28
CVE-2026-75486
CVE-2026-75486 is a command injection vulnerability in Synk Sweater Comb before version 3.8.8. An attacker controlling the .vervet.yaml configuration file can execute arbitrary OS commands by injecting malicious input into the linters.<key>.optic-ci.original branch name field. The vulnerability is due to the expectGitBranch() function in src/lint.ts passing the unsanitized branch name directly into child_ [truncated]