<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:17:42.897000+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0753</id>
    <title>certfr-2026-avi-0753 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer un p…</title>
    <updated>2026-10-04T15:17:42.905427+00:00</updated>
    <content>certfr-2026-avi-0753</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0753"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336765</id>
    <title>EUVD-2026-336765</title>
    <updated>2026-10-04T15:17:42.905467+00:00</updated>
    <content>EUVD-2026-336765</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40034</id>
    <title>fkie_cve-2026-40034</title>
    <updated>2026-10-04T15:17:42.905482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f26g-jm89-4g65</id>
    <title>GHSA-f26g-jm89-4g65 — gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Exec…</title>
    <updated>2026-10-04T15:17:42.905510+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: gix</p>
<p>### Summary</p>
<p>[`gix_submodule::File::update()`](https://github.com/GitoxideLabs/gitoxide/blob/main/gix-submodule/src/access.rs#L168) is the API that gates whether an attacker-supplied `.gitmodules` file may set `update = !&lt;shell command&gt;`. The function is designed to return `Err(CommandForbiddenInModulesConfiguration)` unless the `!command` value came from a trusted local source (`.git/config`). Git CVE [CVE-2019-19604](https://nvd.nist.gov/vuln/detail/cve-2019-19604) illustrates why this check is necessary.</p>
<p>However, the guard is implemented incorrectly: it checks whether any section with the same submodule name exists from a non-`.gitmodules` source; it does not verify that the `update` value came from that section.</p>
<p>Once a submodule has been initialized (any workflow that writes `submodule.&lt;name&gt;.url` to `.git/config`), and the attacker subsequently adds `update = !cmd` to `.gitmodules`, the guard passes while the command value falls through to the attacker-controlled file.</p>
<p>On an identical repository state, `git submodule update` aborts with `fatal: invalid value for 'submodule.sub.update'`, while `gix::Submodule::update()` returns `Ok(Some(Update::Command("touch /tmp/pwned")))`.</p>
<p>The vulnerable code was introduced in https://github.com/GitoxideLabs/gitoxide/commit/6a2e6a436f76c8bbf2487f9967413a51356667a0.</p>
<p>### Details</p>
<p>The vulnerable method is `gix_submodule::File::update`: https://github.com/GitoxideLabs/gitoxide/blob/main/gix-submodule/src/access.rs#L168-L193:</p>
<p>```rust…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f26g-jm89-4g65"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-40034</id>
    <title>msrc_CVE-2026-40034 — gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule</title>
    <updated>2026-10-04T15:17:42.905589+00:00</updated>
    <content>msrc_CVE-2026-40034</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-40034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11038-1</id>
    <title>openSUSE-SU-2026:11038-1 — stgit-2.6.0-1.1 on GA media</title>
    <updated>2026-10-04T15:17:42.905606+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>stgit-2.6.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11038-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40034</id>
    <title>UBUNTU-CVE-2026-40034</title>
    <updated>2026-10-04T15:17:42.905621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: rust-gix, Ubuntu:25.10: rust-gix-submodule, Ubuntu:26.04:LTS: rust-gix, Ubuntu:26.04:LTS: rust-gix-submodule</p>
<p>gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40034"/>
  </entry>
</feed>
