{"id":"GHSA-x4ff-q6h8-v7gw","summary":"sbt: Source dependency feature (via crafted VCS URL) leads to arbitrary code execution on Windows","details":"### Summary\nOn Windows, sbt uses `Process(\"cmd\", \"/c\", ...)` to run VCS commands (git, hg, svn). The URI fragment (branch, tag, revision) is user-controlled via the build definition and passed to these commands without validation. Because `cmd /c` interprets `&`, `|`, and `;` as command separators, a malicious fragment can execute arbitrary commands.\n\n### Patched version\n\nTechnically, sbt 1.12.7 is patched, but it has a bug that makes source dependency non-functional, so update to **sbt 1.12.8** or later instead.\n\n### Details\n- [Resolvers.scala L84–95](https://github.com/sbt/sbt/blob/dc90f160dfb563f46fd1a7b97945c381d15e2a6c/main/src/main/scala/sbt/Resolvers.scala#L84-L95) — git resolver passes `uri.getFragment()` to `run()` without sanitization\n- [Resolvers.scala L137–145](https://github.com/sbt/sbt/blob/dc90f160dfb563f46fd1a7b97945c381d15e2a6c/main/src/main/scala/sbt/Resolvers.scala#L137-L145) — `run()` uses `Process(\"cmd\", \"/c\", ...)` on Windows, so `cmd` interprets `&&` as command separator\n\n### PoC\n```sh\n# build.properties\n# sbt.version=1.12.5  # Tested on those two versions of sbt\nsbt.version=2.0.0-RC9\n```\n\n```scala\n// build.sbt\n\nThisBuild / scalaVersion := \"2.12.19\"\n\nlazy val root = project\n  .in(file(\".\"))\n  .dependsOn(vulnerable)\n\nlazy val vulnerable = RootProject(\n  uri(\"https://github.com/sbt/io.git#develop%26%26calc.exe\")\n)\n```\n\n### Impact\n\nWindows users are impacted. An attacker can execute arbitrary Windows commands if they control the dependency URI.","aliases":["CVE-2026-32948"],"modified":"2026-03-27T22:05:00.945121Z","published":"2026-03-24T16:04:12Z","database_specific":{"cwe_ids":["CWE-78"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-24T16:04:12Z","nvd_published_at":"2026-03-24T20:16:27Z"},"references":[{"type":"WEB","url":"https://github.com/sbt/sbt/security/advisories/GHSA-x4ff-q6h8-v7gw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32948"},{"type":"WEB","url":"https://github.com/sbt/sbt/commit/1ce945b6b79cbe3cef6c0fe9efbbd2904e0f479e"},{"type":"WEB","url":"https://github.com/sbt/sbt/commit/3a474ab060df4dbfa825a7e7bc97e00056519800"},{"type":"PACKAGE","url":"https://github.com/sbt/sbt"},{"type":"WEB","url":"https://github.com/sbt/sbt/releases/tag/v1.12.7"}],"affected":[{"package":{"name":"org.scala-sbt:sbt","ecosystem":"Maven","purl":"pkg:maven/org.scala-sbt/sbt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.9.5"},{"fixed":"1.12.8"}]}],"versions":["0.99.2","0.99.4","1.0.0","1.0.0-M1","1.0.0-M2","1.0.0-M3","1.0.0-M4","1.0.0-M5","1.0.0-M6","1.0.0-RC1","1.0.0-RC2","1.0.0-RC3","1.0.1","1.0.2","1.0.3","1.0.4","1.1.0","1.1.0-M1","1.1.0-RC1","1.1.0-RC2","1.1.0-RC3","1.1.0-RC4","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.10.0","1.10.0-M1","1.10.0-RC1","1.10.0-RC2","1.10.1","1.10.10","1.10.11","1.10.2","1.10.3","1.10.4","1.10.5","1.10.6","1.10.7","1.10.8","1.10.9","1.11.0","1.11.0-RC1","1.11.0-RC2","1.11.1","1.11.2","1.11.3","1.11.4","1.11.5","1.11.6","1.11.7","1.12.0","1.12.0-M1","1.12.0-M2","1.12.0-RC1","1.12.1","1.12.2","1.12.3","1.12.4","1.12.5","1.12.6","1.12.7","1.2.0","1.2.0-M1","1.2.0-RC1","1.2.0-RC2","1.2.0-RC3","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.3.0","1.3.0-M1","1.3.0-M2","1.3.0-M3","1.3.0-M4","1.3.0-M5","1.3.0-M5-94d5ec","1.3.0-RC1","1.3.0-RC2","1.3.0-RC3","1.3.0-RC4","1.3.0-RC5","1.3.1","1.3.10","1.3.11","1.3.12","1.3.13","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9","1.4.0","1.4.0-M1","1.4.0-M2","1.4.0-RC1","1.4.0-RC2","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","1.5.0","1.5.0-M1","1.5.0-M2","1.5.0-RC1","1.5.0-RC2","1.5.1","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.6.0","1.6.0-M1","1.6.0-RC1","1.6.0-RC2","1.6.1","1.6.2","1.7.0","1.7.0-M1","1.7.0-M2","1.7.0-M2-6810fix","1.7.0-M3","1.7.0-RC1","1.7.0-RC2","1.7.1","1.7.2","1.7.3","1.8.0","1.8.0-RC1","1.8.1","1.8.2","1.8.3","1.9.0","1.9.0-M1","1.9.0-RC1","1.9.0-RC2","1.9.0-RC3","1.9.1","1.9.2","1.9.3","1.9.4","1.9.5","1.9.6","1.9.7","1.9.8","1.9.9"],"database_specific":{"last_known_affected_version_range":"\u003c 1.12.7","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-x4ff-q6h8-v7gw/GHSA-x4ff-q6h8-v7gw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}