A critical OS command injection vulnerability (CVE-2026-82668) has been identified in klaussilveira GitList version 2.0.0. The vulnerability exists in the getDefaultBranch function within src/SCM/System/Git/CommandLine.php of the Git Command Line component. An attacker can exploit this flaw remotely to execute arbitrary OS commands. The exploit has been publicly disclosed and is available for use, increasing the risk of active exploitation. A patch has been released and is identified by commit 88cf2866083d5f7c20d9d565c45f828a7ad1516b. Users are strongly advised to upgrade to GitList version 3.0.0-beta to remediate the vulnerability. No workaround is mentioned other than upgrading the affected component.