Junglewise Threat Intelligence

CVE-2026-75486: Snyk Sweater Comb command injection in configuration parsing

CVE-2026-75486 · Severity: high · CVSS 8 · Published 2026-08-28

Vendors: Snyk.

Executive brief

Sweater Comb is a Node.js linting tool used to validate API specifications in development repositories. An attacker who crafts a malicious repository configuration file can execute arbitrary operating system commands when a developer or CI pipeline runs the linting tool against that repository, potentially exposing credentials, SSH keys, and sensitive source code.

Technical details

The vulnerability is a command injection flaw in the expectGitBranch() function in src/lint.ts. The function passes an unsanitized branch name parameter directly into child_process.exec() via a template literal without escaping or validation. The branch name is sourced from the linters.<key>.optic-ci.original field in .vervet.yaml, which is fully attacker-controlled in a malicious repository. Since child_process.exec() invokes /bin/sh -c, shell metacharacters in the branch name are interpreted and executed. An attacker can inject commands by crafting a .vervet.yaml file with malicious payloads (e.g., "main; touch /tmp/canary") and committing it to a repository. When a developer or CI pipeline runs sweater-comb lint against that repository, the injected commands execute with the privileges of the user running the tool. The fix is to replace child_process.exec() with child_process.execFile() using an argument array to prevent shell interpretation.

Affected products

  • Snyk Sweater Comb before 3.8.8

Timeline

  • 2026-08-28: disclosed: CVE-2026-75486 published
  • 2026-08-27: patched: Fix merged in PR #743 with commit 05a0eec

References