<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T01:00:22.601526+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-349327</id>
    <title>EUVD-2026-349327</title>
    <updated>2026-10-10T01:00:22.666771+00:00</updated>
    <content>EUVD-2026-349327</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-349327"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67434</id>
    <title>fkie_cve-2026-67434</title>
    <updated>2026-10-10T01:00:22.666809+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as " and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-67434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hmqg-cxww-wqhq</id>
    <title>GHSA-hmqg-cxww-wqhq — PHP_CodeSniffer gitblame report command injection via crafted filename</title>
    <updated>2026-10-10T01:00:22.666847+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: squizlabs/php_codesniffer</p>
<p>### Impact</p>
<p>PHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the `Gitblame`, `Hgblame` and `Svnblame` report(s).</p>
<p>As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the `Gitblame`, `Hgblame` or `Svnblame` report(s) would process a file whose name contains shell metacharacters.</p>
<p>* Users using the default `Full` report, or any of the other non-*blame reports, are not affected.
* Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as `"` and `;`, are not affected.</p>
<p>### Patched versions</p>
<p>The issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience.</p>
<p>### Workaround</p>
<p>Users of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the `Gitblame`, `Hgblame` or the `Svnblame` reports when scanning untrusted code.</p>
<p>This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees.</p>
<p>### Credits</p>
<p>Many thanks to both [@Faze-up](https://github.com/Faze-up) and [@edorian](https://github.com/edorian) for responsibly disclosing this vulnerability.</p>
<p>### How can I report a security bug?</p>
<p>Pleas…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hmqg-cxww-wqhq"/>
  </entry>
</feed>
