<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:33:15.385386+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-pdm-cve-2026-47781</id>
    <title>BREW-pdm-CVE-2026-47781 — pdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing</title>
    <updated>2026-10-03T13:33:15.528544+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: pdm</p>
<p>PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is parsed. This happens because load_plugins() runs during Core.init() and adds .pdm-plugins via site.addsitedir(), which processes .pth files and immediately executes any line beginning with import, so the code runs with the privileges of the user invoking pdm and even a benign command such as pdm --version triggers it (making the impact strongest in CI, automation, and privileged contexts). The issue is fixed in version 2.27.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-pdm-cve-2026-47781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348513</id>
    <title>EUVD-2026-348513</title>
    <updated>2026-10-03T13:33:15.528613+00:00</updated>
    <content>EUVD-2026-348513</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348513"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47781</id>
    <title>fkie_cve-2026-47781</title>
    <updated>2026-10-03T13:33:15.528630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is parsed. This happens because load_plugins() runs during Core.init() and adds .pdm-plugins via site.addsitedir(), which processes .pth files and immediately executes any line beginning with import, so the code runs with the privileges of the user invoking pdm and even a benign command such as pdm --version triggers it (making the impact strongest in CI, automation, and privileged contexts). The issue is fixed in version 2.27.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qq6c-99pv-prvf</id>
    <title>GHSA-qq6c-99pv-prvf — PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing</title>
    <updated>2026-10-03T13:33:15.528685+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pdm</p>
<p>## Summary</p>
<p>PDM automatically loads project-local plugin paths from `.pdm-plugins` during `Core` initialization. Because this path is added via `site.addsitedir()`, attacker-controlled `.pth` files inside the project plugin directory are processed and can execute Python code before normal CLI handling begins.</p>
<p>This allows arbitrary code execution with the privileges of the user running `pdm` from an untrusted repository checkout.</p>
<p>## Affected Behavior</p>
<p>- Trigger does not require `pdm install --plugins`
- A low-impact command such as `pdm --version` is sufficient
- Impact is strongest in CI, privileged shells, and automation contexts</p>
<p>## Affected Code</p>
<p>- `src/pdm/core.py:74-82`
- `src/pdm/core.py:310-333`
- `src/pdm/core.py:335-352`</p>
<p>## Technical Details</p>
<p>`Core.__init__()` calls `load_plugins()` before ordinary command execution. `load_plugins()` calls `_add_project_plugins_library()`, which derives the project-local `.pdm-plugins` library path and adds it through `site.addsitedir()`.</p>
<p>On CPython, `site.addsitedir()` processes `.pth` files found in the added directory. `.pth` lines beginning with `import ` are executed immediately. This creates a trust-boundary break: project-controlled files execute before the user explicitly opts into plugin installation or plugin loading.</p>
<p>## Impact</p>
<p>- Arbitrary code execution as the invoking user
- Potential credential theft, persistence, or workspace tampering
- Potential privilege escalation when `pdm` is run via `sudo`, root-owned CI j…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qq6c-99pv-prvf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11124-1</id>
    <title>openSUSE-SU-2026:11124-1 — python311-pdm-2.28.0-1.1 on GA media</title>
    <updated>2026-10-03T13:33:15.528751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-pdm-2.28.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11124-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2863</id>
    <title>PYSEC-2026-2863 — PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing</title>
    <updated>2026-10-03T13:33:15.528773+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pdm</p>
<p>## Summary</p>
<p>PDM automatically loads project-local plugin paths from `.pdm-plugins` during `Core` initialization. Because this path is added via `site.addsitedir()`, attacker-controlled `.pth` files inside the project plugin directory are processed and can execute Python code before normal CLI handling begins.</p>
<p>This allows arbitrary code execution with the privileges of the user running `pdm` from an untrusted repository checkout.</p>
<p>## Affected Behavior</p>
<p>- Trigger does not require `pdm install --plugins`
- A low-impact command such as `pdm --version` is sufficient
- Impact is strongest in CI, privileged shells, and automation contexts</p>
<p>## Affected Code</p>
<p>- `src/pdm/core.py:74-82`
- `src/pdm/core.py:310-333`
- `src/pdm/core.py:335-352`</p>
<p>## Technical Details</p>
<p>`Core.__init__()` calls `load_plugins()` before ordinary command execution. `load_plugins()` calls `_add_project_plugins_library()`, which derives the project-local `.pdm-plugins` library path and adds it through `site.addsitedir()`.</p>
<p>On CPython, `site.addsitedir()` processes `.pth` files found in the added directory. `.pth` lines beginning with `import ` are executed immediately. This creates a trust-boundary break: project-controlled files execute before the user explicitly opts into plugin installation or plugin loading.</p>
<p>## Impact</p>
<p>- Arbitrary code execution as the invoking user
- Potential credential theft, persistence, or workspace tampering
- Potential privilege escalation when `pdm` is run via `sudo`, root-owned CI j…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-47781</id>
    <title>UBUNTU-CVE-2026-47781</title>
    <updated>2026-10-03T13:33:15.528818+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:26.04:LTS: pdm</p>
<p>PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is parsed. This happens because load_plugins() runs during Core.init() and adds .pdm-plugins via site.addsitedir(), which processes .pth files and immediately executes any line beginning with import, so the code runs with the privileges of the user invoking pdm and even a benign command such as pdm --version triggers it (making the impact strongest in CI, automation, and privileged contexts). The issue is fixed in version 2.27.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-47781"/>
  </entry>
</feed>
