Junglewise Threat Intelligence

CVE-2026-14722: tiddly-gittly TidGi-Desktop code injection in Git Repository Import

CVE-2026-14722 · Severity: high · CVSS 7.3 · Published 2026-07-05

Vendors: npm.

Executive brief

TidGi-Desktop, a personal knowledge management and note-taking application, is vulnerable to a critical security flaw during the import of TiddlyWiki repositories. If a user imports a specially crafted malicious repository, the application will automatically execute hidden code contained within the files. This could allow an attacker to take complete control of the user's computer, access sensitive files, or install malware.

Technical details

A remote code execution (RCE) vulnerability exists in TidGi-Desktop up to version 0.13.0 within the Git Repository Import component. The flaw resides in the interaction between TidGi's wiki loading service (loadWikiTiddlersWithSubWikis.ts) and the underlying TiddlyWiki boot process. When a wiki is imported, the application automatically loads .tid files into the wiki store; if a file contains a 'module-type' field set to 'startup' and a 'type' of 'application/javascript', TiddlyWiki's boot.js registers and executes it during the startup sequence. An attacker can exploit this by providing a malicious repository containing a JavaScript payload that uses Node.js 'require' to execute arbitrary shell commands. No authentication is required, though the attack relies on the user performing a repository import.

Affected products

  • tiddly-gittly TidGi-Desktop up to 0.13.0

Timeline

  • 2026-06-04: advisory: GitHub Security Advisory published by researcher
  • 2026-07-05: disclosed: NVD publication date

References

Related threats