<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:04:21.889185+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-cloudflare-wrangler-cve-2026-0933</id>
    <title>BREW-cloudflare-wrangler-CVE-2026-0933 — Wrangler affected by OS Command Injection in `wrangler pages deploy`</title>
    <updated>2026-10-06T17:04:21.978432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: cloudflare-wrangler</p>
<p>**Summary**</p>
<p>A command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler.</p>
<p>**Root cause**</p>
<p>The `commitHash` variable, derived from user input via the `--commit-hash` CLI argument, is interpolated directly into a shell command using template literals (e.g., ``execSync(`git show -s --format=%B ${commitHash}`)``). Shell metacharacters are interpreted by the shell, enabling command execution.</p>
<p>**Impact**</p>
<p>This vulnerability is generally hard to exploit, as it requires `--commit-hash` to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the `--commit-hash` parameter is populated from external, potentially untrusted sources. An attacker could exploit this to:</p>
<p>- Run any shell command.
- Exfiltrate environment variables.
- Compromise the CI runner to install backdoors or modify build artifacts.</p>
<p>**Mitigation**</p>
<p>- Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher. 
- Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher. 
- Users on Wrangler v2 (EOL) should upgrade to a supported major version.</p>
<p>**Credits**</p>
<p>Disclosed responsibly by kny4hacker.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-cloudflare-wrangler-cve-2026-0933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266523</id>
    <title>EUVD-2026-266523</title>
    <updated>2026-10-06T17:04:21.978508+00:00</updated>
    <content>EUVD-2026-266523</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-0933</id>
    <title>fkie_cve-2026-0933</title>
    <updated>2026-10-06T17:04:21.978527+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler.</p>
<p>Root causeThe commitHash variable, derived from user input via the --commit-hash CLI argument, is interpolated directly into a shell command using template literals (e.g.,  execSync(`git show -s --format=%B ${commitHash}`)). Shell metacharacters are interpreted by the shell, enabling command execution.</p>
<p>ImpactThis vulnerability is generally hard to exploit, as it requires --commit-hash to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the</p>
<p>--commit-hash parameter is populated from external, potentially untrusted sources. An attacker could exploit this to:</p>
<p>*  Run any shell command.
  *  Exfiltrate environment variables.
  *  Compromise the CI runner to install backdoors or modify build artifacts.</p>
<p>Credits Disclosed responsibly by kny4hacker.</p>
<p>Mitigation
  *  Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher.
  *  Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher.
  *  Users on Wrangler v2 (EOL) should upgrade to a supported major version.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-0933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-36p8-mvp6-cv38</id>
    <title>GHSA-36p8-mvp6-cv38 — Wrangler affected by OS Command Injection in `wrangler pages deploy`</title>
    <updated>2026-10-06T17:04:21.978566+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: wrangler</p>
<p>**Summary**</p>
<p>A command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler.</p>
<p>**Root cause**</p>
<p>The `commitHash` variable, derived from user input via the `--commit-hash` CLI argument, is interpolated directly into a shell command using template literals (e.g., ``execSync(`git show -s --format=%B ${commitHash}`)``). Shell metacharacters are interpreted by the shell, enabling command execution.</p>
<p>**Impact**</p>
<p>This vulnerability is generally hard to exploit, as it requires `--commit-hash` to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the `--commit-hash` parameter is populated from external, potentially untrusted sources. An attacker could exploit this to:</p>
<p>- Run any shell command.
- Exfiltrate environment variables.
- Compromise the CI runner to install backdoors or modify build artifacts.</p>
<p>**Mitigation**</p>
<p>- Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher. 
- Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher. 
- Users on Wrangler v2 (EOL) should upgrade to a supported major version.</p>
<p>**Credits**</p>
<p>Disclosed responsibly by kny4hacker.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-36p8-mvp6-cv38"/>
  </entry>
</feed>
