<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T16:09:21.298862+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368841</id>
    <title>EUVD-2026-368841</title>
    <updated>2026-10-10T16:09:21.356709+00:00</updated>
    <content>EUVD-2026-368841</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57586</id>
    <title>fkie_cve-2026-57586</title>
    <updated>2026-10-10T16:09:21.356764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke _sync_gradle. _sync_gradle prefers a repository-controlled gradlew or gradlew.bat file and passes it directly to asyncio.create_subprocess_exec with the repository root as the working directory; validate_path in code_rag/core/utils.py constrains the directory location but does not validate the executable's content or integrity. A victim who indexes an attacker-controlled Gradle repository therefore executes attacker-supplied code with the victim's operating-system privileges, allowing disclosure, modification, persistence, or denial of service in the user environment. This issue is fixed in 1.3.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-57586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wg5p-8h9p-3mr7</id>
    <title>GHSA-wg5p-8h9p-3mr7 — agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution</title>
    <updated>2026-10-10T16:09:21.356822+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: agent-coderag</p>
<p>## Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution</p>
<p>### Summary</p>
<p>`agent-coderag` unconditionally executes a repository-controlled `gradlew` script during its default `sync` dependency-discovery flow. An attacker who can induce a victim to index a malicious Gradle repository (one containing `build.gradle` and a crafted `gradlew`) achieves arbitrary code execution with the victim's OS privileges. No authentication, no extra flags, and no elevated permissions are required; the attack fires on the default `agent-coderag sync &lt;path&gt;` invocation.</p>
<p>### Details</p>
<p>The vulnerability exists across a four-step call chain in the `sync` command:</p>
<p>**1. Entry point — `code_rag/entry/cli.py:70`**</p>
<p>```python
await manager.sync_dependencies(args.path or ".")
```</p>
<p>`sync_dependencies()` is called unconditionally before indexing. There is no opt-in flag; any `agent-coderag sync` invocation triggers dependency discovery.</p>
<p>**2. Gradle project detection — `code_rag/core/manager.py:40-47`**</p>
<p>The presence of a `build.gradle` or `build.gradle.kts` file in the target directory is sufficient to invoke `_sync_gradle()`. No additional checks are performed.</p>
<p>**3. Wrapper selection — `code_rag/core/manager.py:110-113`**</p>
<p>```python
gradle_wrapper = root / ("gradlew.bat" if os.name == "nt" else "gradlew")
gradle_bin: Optional[str] = None
if gradle_wrapper.exists():
    gradle_bin = str(gradle_wrapper.resolve())
else:
    gradle_bin = shutil.which("gradle")
```</p>
<p>When a repos…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wg5p-8h9p-3mr7"/>
  </entry>
</feed>
