{"id":"GHSA-23f7-99jx-m54r","summary":"Remote code execution in dependabot-core branch names when cloning","details":"### Impact\nRemote code execution vulnerability in `dependabot-common` and  `dependabot-go_modules` when a source branch name contains malicious injectable bash code.\n\nFor example, if Dependabot is configured to use the following source branch name: `\"/$({curl,127.0.0.1})\"`, Dependabot will make a HTTP request to the following URL: 127.0.0.1 when cloning the source repository.\n\nWhen Dependabot is configured to clone the source repository during an update, Dependabot runs a shell command to git clone the repository:\n\n```bash\ngit clone --no-tags --no-recurse-submodules --depth=1 --branch=\u003cBRANCH\u003e --single-branch \u003cGITHUB_REPO_URL\u003e repo/contents/path\n```\n\nDependabot will always clone the source repository for `go_modules` during the file fetching step and can be configured to clone the repository for other package managers using the `FileFetcher` class from `dependabot-common`.\n\n```ruby\nsource = Dependabot::Source.new(\n  provider: \"github\",\n  repo: \"repo/name\",\n  directory: \"/\",\n  branch: \"/$({curl,127.0.0.1})\",\n)\n\nrepo_contents_path = \"./file/path\"\nfetcher = Dependabot::FileFetchers.for_package_manager(\"bundler\").\n                  new(source: source, credentials: [],\n                  repo_contents_path: repo_contents_path)\nfetcher.clone_repo_contents\n```\n\n### Patches\n\nThe fix was applied to version `0.125.1`: https://github.com/dependabot/dependabot-core/pull/2727\n\n### Workarounds\nEscape the branch name prior to passing it to the `Dependabot::Source` class.\n\nFor example using `shellwords`:\n\n```ruby\nrequire \"shellwords\"\nbranch = Shellwords.escape(\"/$({curl,127.0.0.1})\")\nsource = Dependabot::Source.new(\n  provider: \"github\",\n  repo: \"repo/name\",\n  directory: \"/\",\n  branch: branch,\n)\n```","aliases":["CVE-2020-26222"],"modified":"2026-01-30T02:35:34.926009Z","published":"2020-11-13T15:47:50Z","related":["CVE-2020-26222"],"database_specific":{"cwe_ids":["CWE-74"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-11-13T15:47:18Z","nvd_published_at":"2020-11-13T16:15:18Z"},"references":[{"type":"WEB","url":"https://github.com/dependabot/dependabot-core/security/advisories/GHSA-23f7-99jx-m54r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26222"},{"type":"WEB","url":"https://github.com/dependabot/dependabot-core/pull/2727"},{"type":"WEB","url":"https://github.com/dependabot/dependabot-core/commit/e089116abbe284425b976f7920e502b8e83a61b5"},{"type":"PACKAGE","url":"https://github.com/dependabot/dependabot-core"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/dependabot-common/CVE-2020-26222.yml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/dependabot-omnibus/CVE-2020-26222.yml"},{"type":"WEB","url":"https://rubygems.org/gems/dependabot-common"},{"type":"WEB","url":"https://rubygems.org/gems/dependabot-omnibus"}],"affected":[{"package":{"name":"dependabot-omnibus","ecosystem":"RubyGems","purl":"pkg:gem/dependabot-omnibus"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.119.0.beta1"},{"fixed":"0.125.1"}]}],"versions":["0.119.0","0.119.0.beta1","0.119.1","0.119.2","0.119.3","0.119.4","0.119.5","0.119.6","0.120.0","0.120.1","0.120.2","0.120.3","0.120.4","0.120.5","0.121.0","0.121.1","0.122.0","0.122.1","0.123.0","0.123.1","0.124.0","0.124.1","0.124.2","0.124.3","0.124.4","0.124.5","0.124.6","0.124.7","0.124.8","0.125.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-23f7-99jx-m54r/GHSA-23f7-99jx-m54r.json"}},{"package":{"name":"dependabot-common","ecosystem":"RubyGems","purl":"pkg:gem/dependabot-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.119.0.beta1"},{"fixed":"0.125.1"}]}],"versions":["0.119.0","0.119.0.beta1","0.119.1","0.119.2","0.119.3","0.119.4","0.119.5","0.119.6","0.120.0","0.120.1","0.120.2","0.120.3","0.120.4","0.120.5","0.121.0","0.121.1","0.122.0","0.122.1","0.123.0","0.123.1","0.124.0","0.124.1","0.124.2","0.124.3","0.124.4","0.124.5","0.124.6","0.124.7","0.124.8","0.125.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-23f7-99jx-m54r/GHSA-23f7-99jx-m54r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}