Junglewise Threat Intelligence

CVE-2026-31862: @siteboon/claude-code-ui command injection in Git endpoints

CVE-2026-31862 · Severity: low · CVSS 3.1 · Published 2026-03-11

Technologies: Siteboon Claude-Code-Ui. Vendors: npm, Siteboon.

Executive brief

@siteboon/claude-code-ui is a Node.js application that provides a web-based interface for Git repository operations. Multiple Git API endpoints are vulnerable to command injection, allowing authenticated users to execute arbitrary operating system commands with the privileges of the Node.js process. This can lead to complete server compromise, data theft, or injection of malicious code into the repository.

Technical details

The vulnerability exists in server/routes/git.js where multiple endpoints use execAsync() to execute shell commands with user-supplied parameters (file paths, branch names, commit messages, and commit hashes) directly interpolated into command strings. The application attempts basic escaping of double quotes but this is easily bypassed using shell metacharacters such as $(command), `command`, semicolons, &&, ||, and newlines. Affected endpoints include GET /api/git/diff, POST /api/git/commit, POST /api/git/checkout, and others. Authentication is required to reach these endpoints, but once authenticated, an attacker can inject arbitrary commands. The fix replaces all vulnerable execAsync() calls with spawnAsync() (using child_process.spawn with shell: false) so that user input is passed as discrete arguments rather than interpreted by a shell. Additional allowlist validation using /^[0-9a-f]{4,64}$/i was added for commit hashes.

Affected products

  • siteboon claude-code-ui <=1.23.0

Timeline

  • 2026-03-11: disclosed: CVE-2026-31862 and GHSA-f2fc-vc88-6w7q published
  • 2026-03-11: patched: Fix released in version 1.24.0 (commit 55567f4)

References

Related threats