Executive brief
Repomix is a tool used to package entire code repositories into a single file for use with AI models. A security flaw in its web-based service allows unauthenticated users to trick the server into reading local files and private Git repositories stored on the server's own hard drive. This could lead to the exposure of sensitive internal source code or configuration files, potentially compromising the security of the hosting infrastructure.
Technical details
A local file inclusion (LFI) vulnerability exists in the Repomix web backend due to insufficient validation of user-supplied repository URLs. The 'isValidRemoteValue' function in 'src/core/git/gitRemoteParse.ts' fails to restrict the 'file://' URI scheme. When an attacker provides a 'file://' URL, the 'git-url-parse' utility extracts a path that satisfies the application's shorthand validation patterns, allowing the URL to be passed directly to a 'git clone' command. An unauthenticated remote attacker can exploit this to clone and read any local Git repository accessible on the server's filesystem. This issue has been addressed in version 1.14.1 by enforcing an HTTPS-only allowlist for remote repository URLs.
Affected products
- repomix repomix < 1.14.1
Timeline
- 2026-06-02: disclosed: Initial report to maintainers
- 2026-07-06: patched: Fix committed to repository
- 2026-07-08: advisory: CVE-2026-59703 published