<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T00:09:38.002670+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-379756</id>
    <title>EUVD-2026-379756</title>
    <updated>2026-10-07T00:09:38.047475+00:00</updated>
    <content>EUVD-2026-379756</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-379756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-102828</id>
    <title>fkie_cve-2026-102828</title>
    <updated>2026-10-07T00:09:38.047511+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.&lt;token&gt;.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-102828"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x6jw-m9v5-85vh</id>
    <title>GHSA-x6jw-m9v5-85vh — simple-git unsafe-operation guard does not block trailer command configuration</title>
    <updated>2026-10-07T00:09:38.047547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: simple-git</p>
<p>## Affected product</p>
<p>The default `blockUnsafeOperationsPlugin` in `simple-git` when an application permits untrusted values to reach `SimpleGitOptions.config` or Git inline configuration arguments such as `-c &lt;key&gt;=&lt;value&gt;`.</p>
<p>## Summary</p>
<p>`trailer.&lt;token&gt;.cmd` is not recognized as unsafe by the default guard. Therefore, a configured inline value reaches Git without a `GitPluginError`.</p>
<p>Git documents `trailer.&lt;token&gt;.cmd` as a shell command invoked by `git interpret-trailers`. An application that relies on the default plugin to reject unsafe configuration can therefore execute a command supplied through an untrusted trailer-command configuration value.</p>
<p>## Technical details</p>
<p>`simple-git/src/lib/git-factory.ts` installs `commandConfigPrefixingPlugin` before `blockUnsafeOperationsPlugin`. The prefixing plugin in `simple-git/src/lib/plugins/command-config-prefixing-plugin.ts` turns every `SimpleGitOptions.config` entry into `-c &lt;key&gt;=&lt;value&gt;` before the unsafe-operation plugin evaluates the final argv.</p>
<p>In `simple-git@3.36.0`, `blockUnsafeOperationsPlugin` delegates to `@simple-git/argv-parser`. `packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts` compares parsed configuration writes against `preventUnsafeConfig`. That list has no matcher for `trailer.&lt;token&gt;.cmd`, so the invocation is allowed.</p>
<p>Git v2.39.5's `Documentation/git-interpret-trailers.txt` states that `trailer.&lt;token&gt;.cmd` specifies a shell command called to generate or modify a trailer.</p>
<p>## P…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x6jw-m9v5-85vh"/>
  </entry>
</feed>
