<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T13:48:57.611388+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248816</id>
    <title>EUVD-2026-248816</title>
    <updated>2026-10-05T13:48:57.661139+00:00</updated>
    <content>EUVD-2026-248816</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248816"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54586</id>
    <title>fkie_cve-2025-54586</title>
    <updated>2026-10-05T13:48:57.661180+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below,   attackers can inject extra commits into the pack sent to GitHub, commits that aren’t pointed to by any branch. Although these “hidden” commits never show up in the repository’s visible history, GitHub still serves them at their direct commit URLs. This lets an attacker exfiltrate sensitive data without ever leaving a trace in the branch view. We rate this a High‑impact vulnerability because it completely compromises repository confidentiality. This is fixed in version 1.19.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-54586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v98g-8rqx-g93g</id>
    <title>GHSA-v98g-8rqx-g93g — GitProxy Hidden Commits Injection</title>
    <updated>2026-10-05T13:48:57.661218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @finos/git-proxy</p>
<p>### Summary
An attacker can inject extra commits into the pack sent to GitHub, commits that aren’t pointed to by any branch. Although these “hidden” commits never show up in the repository’s visible history, GitHub still serves them at their direct commit URLs. This lets an attacker exfiltrate sensitive data without ever leaving a trace in the branch view. We rate this a High‑impact vulnerability because it completely compromises repository confidentiality.</p>
<p>### Details</p>
<p>The proxy currently trusts only the ref‑update line (`oldOid → newOid`) and doesn't inspect the packfile’s contents</p>
<p>Because the code only runs `git rev-list oldOid..newOid` to compute **introducedCommits** but **never** checks which commits actually arrived in the pack, a malicious client can append extra commits. Those “hidden” commits won’t be pointed to by any branch but GitHub still stores and serves them by SHA. 
&lt;img width="2556" height="744" alt="Screenshot 2025-07-16 at 12 29 19" src="https://github.com/user-attachments/assets/abf459a9-310b-4819-a989-797c7e871790" /&gt;</p>
<p>### PoC</p>
<p>#### Prerequisites</p>
<p>-   A GitHub Personal Access Token stored in `~/.github-test-pat`.
-   A test repository also registered in git-proxy, e.g. `your-org/test-repo.git`, to which you have push rights.</p>
<p>#### 1. Prepare the “visible” and “hidden” commits</p>
<p>```bash
# Clone the test repository
git clone http://localhost:8000/your-org/test-repo.git
cd test-repo</p>
<p># 1. Record the original HEAD
ORIG_COMMIT=$(git rev-parse HEAD)</p>
<p># 2. C…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v98g-8rqx-g93g"/>
  </entry>
</feed>
