CVE-2026-12171 - auto-changelog: code execution via untrusted in-repository configuration (handlebarsSetup/plugins), plus argument injection, path traversal, and SSRF
CVE ID :CVE-2026-12171 Published : Oct. 5, 2026, 5:17 p.m. | 2 hours, 11 minutes ago Description :auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors...