Executive brief
Repomix, a tool used to package source code repositories for use with AI models, is vulnerable to a security flaw that allows attackers to execute malicious commands. By providing a specially crafted branch name, an attacker can trick the tool into running unauthorized code on the user's system or build server. This could lead to a full system takeover, theft of sensitive data, or compromise of automated software delivery pipelines.
Technical details
An argument injection vulnerability (CWE-88) exists in Repomix's `src/core/git/gitCommand.ts` within the `execGitShallowClone` function. The application passes the `--remote-branch` CLI value directly to `git fetch` and `git checkout` via `child_process.execFileAsync` without using the `--` or `--end-of-options` delimiters. An attacker can provide a branch name starting with a hyphen (e.g., `--upload-pack=/path/to/payload`) to inject Git options. When combined with local or SSH-style transports, this allows for arbitrary command execution, bypassing the `validateGitUrl()` security checks which were only applied to the repository URL. The issue is fixed in version 1.14.1 by validating branch names and using the `--end-of-options` flag.
Affected products
- yamadashy repomix < 1.14.1
Timeline
- 2026-05-27: patched: Version 1.14.1 released
- 2026-05-27: advisory: GitHub Security Advisory GHSA-9mm9-rqhj-j5mx published
- 2026-07-15: disclosed: CVE-2026-49987 published to NVD