Описание
sbt: Source dependency feature (via crafted VCS URL) leads to arbitrary code execution on Windows
Summary
On Windows, sbt uses Process("cmd", "/c", ...) to run VCS commands (git, hg, svn). The URI fragment (branch, tag, revision) is user-controlled via the build definition and passed to these commands without validation. Because cmd /c interprets &, |, and ; as command separators, a malicious fragment can execute arbitrary commands.
Patched version
Technically, sbt 1.12.7 is patched, but it has a bug that makes source dependency non-functional, so update to sbt 1.12.8 or later instead.
Details
- Resolvers.scala L84–95 — git resolver passes
uri.getFragment()torun()without sanitization - Resolvers.scala L137–145 —
run()usesProcess("cmd", "/c", ...)on Windows, socmdinterprets&&as command separator
PoC
Impact
Windows users are impacted. An attacker can execute arbitrary Windows commands if they control the dependency URI.
Ссылки
- https://github.com/sbt/sbt/security/advisories/GHSA-x4ff-q6h8-v7gw
- https://nvd.nist.gov/vuln/detail/CVE-2026-32948
- https://github.com/sbt/sbt/commit/1ce945b6b79cbe3cef6c0fe9efbbd2904e0f479e
- https://github.com/sbt/sbt/commit/3a474ab060df4dbfa825a7e7bc97e00056519800
- https://github.com/sbt/sbt/releases/tag/v1.12.7
Пакеты
org.scala-sbt:sbt
>= 0.9.5, < 1.12.7
1.12.8
Связанные уязвимости
sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Process("cmd", "/c", ...) to run VCS commands (git, hg, svn). The URI fragment (branch, tag, revision) is user-controlled via the build definition and passed to these commands without validation. Because cmd /c interprets &, |, and ; as command separators, a malicious fragment can execute arbitrary commands. This issue has been patched in version 1.12.7.
sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Process("cmd", "/c", ...) to run VCS commands (git, hg, svn). The URI fragment (branch, tag, revision) is user-controlled via the build definition and passed to these commands without validation. Because cmd /c interprets &, |, and ; as command separators, a malicious fragment can execute arbitrary commands. This issue has been patched in version 1.12.7.