A critical OS command injection vulnerability (CVE-2026-82668) has been identified in klaussilveira GitList version 2.0.0. The vulnerability resides in the getDefaultBranch function within the file src/SCM/System/Git/CommandLine.php of the Git Command Line component. Attackers can exploit this flaw remotely without requiring physical access. A public exploit has been disclosed and may already be in use. The vulnerability allows arbitrary OS command execution through manipulation of the affected function. A patch (commit 88cf2866083d5f7c20d9d565c45f828a7ad1516b) has been released as part of GitList version 3.0.0-beta. Users are strongly advised to upgrade to the patched version immediately to mitigate the risk.