<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T10:52:58.772668+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09077</id>
    <title>bdu:2026-09077</title>
    <updated>2026-10-05T10:52:58.775914+00:00</updated>
    <content>bdu:2026-09077</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318181</id>
    <title>EUVD-2026-318181</title>
    <updated>2026-10-05T10:52:58.775945+00:00</updated>
    <content>EUVD-2026-318181</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318181"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45033</id>
    <title>fkie_cve-2026-45033</title>
    <updated>2026-10-05T10:52:58.775960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a  security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git repository nested inside a project directory can achieve arbitrary code execution when the agent performs git operations. By exploiting git's automatic bare repository discovery during directory traversal, an attacker can set core.fsmonitor or other executable config keys to run arbitrary commands without user awareness or approval. The vulnerability arises because git's core.fsmonitor config key (and 15+ similar keys such as core.hookspath, diff.external, merge.tool, etc.) can specify arbitrary shell commands that git will execute as part of normal operations like status, diff, or rev-parse. This vulnerability is fixed in 1.0.43.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9ccr-r5hg-74gf</id>
    <title>GHSA-9ccr-r5hg-74gf — GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor</title>
    <updated>2026-10-05T10:52:58.775994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @github/copilot</p>
<p>## Summary</p>
<p>A security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git repository nested inside a project directory can achieve arbitrary code execution when the agent performs git operations. By exploiting git's automatic bare repository discovery during directory traversal, an attacker can set `core.fsmonitor` or other executable config keys to run arbitrary commands without user awareness or approval.</p>
<p>## Details</p>
<p>Git supports bare repositories — repositories without a working tree — which can be discovered automatically when git traverses the directory hierarchy looking for a `.git` directory. When git discovers a bare repository, it reads and applies its configuration, including keys that specify external commands to execute.</p>
<p>The vulnerability arises because git's `core.fsmonitor` config key (and 15+ similar keys such as `core.hookspath`, `diff.external`, `merge.tool`, etc.) can specify arbitrary shell commands that git will execute as part of normal operations like `status`, `diff`, or `rev-parse`.</p>
<p>### Attack Scenario</p>
<p>An attacker can exploit this by:</p>
<p>1. Creating a bare git repository nested inside a seemingly normal project directory (e.g., `vendor/malicious.git/` or a deeply nested subdirectory)
2. Configuring `core.fsmonitor` (or similar keys) in that bare repository to execute a malicious command
3. When GitHub Copilot CLI performs any git operation that traverses into or through that directory, git auto-discovers the bare repo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9ccr-r5hg-74gf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1521</id>
    <title>WID-SEC-W-2026-1521 — Microsoft GitHub Copilot: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-05T10:52:58.776047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Microsoft GitHub Copilot ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1521"/>
  </entry>
</feed>
