CVE-2026-75486
Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuratio
CVSS
8.0
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 28, 2026 · Last modified: Aug 28, 2026 · CWE-78
Not enough EPSS history yet.
Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters.<key>.optic-ci.original branch name field. The expectGitBranch() function in src/lint.ts passes the unsanitized branch name directly into child_process.exec() via an unescaped template literal, enabling arbitrary command execution when the lint command is run against the repository.
- github.comhttps://github.com/snyk/sweater-comb/commit/05a0eec4f2acb9ce6d4814016b475504fc64eab2
- github.comhttps://github.com/snyk/sweater-comb/pull/743
- github.comhttps://github.com/snyk/sweater-comb/releases/tag/v3.8.8
- www.vulncheck.comhttps://www.vulncheck.com/advisories/synk-sweater-comb-command-injection-via-vervet-yaml-branch-name