<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T05:35:33.508443+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355460</id>
    <title>EUVD-2026-355460</title>
    <updated>2026-10-07T05:35:33.552554+00:00</updated>
    <content>EUVD-2026-355460</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355460"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-75912</id>
    <title>fkie_cve-2026-75912</title>
    <updated>2026-10-07T05:35:33.552588+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values like --contents=/path/to/file to exfiltrate sensitive files such as SSH keys and credentials through the tool output returned to the model.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-75912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c6mw-8xh8-gpq6</id>
    <title>GHSA-c6mw-8xh8-gpq6 — CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval</title>
    <updated>2026-10-07T05:35:33.552620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: deepseek-tui, npm: deepseek-tui, crates.io: codewhale-tui, npm: codewhale</p>
<p>### Maintainer resolution</p>
<p>The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below.</p>
<p># Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval</p>
<p>## Overview</p>
<p>The `git_blame` tool in DeepSeek-TUI passes the model-supplied `rev` parameter unvalidated into the argv of `git blame`. `git blame` accepts `--contents=&lt;file&gt;`, which causes it to use the file's contents in place of the working tree and echo each line verbatim in the blame output. A `rev` value of `--contents=/path/to/secret` therefore exfiltrates the targeted file's contents into the tool result, which is returned to the model and displayed in the chat transcript.</p>
<p>The tool is registered with `ApprovalRequirement::Auto` and declares `ToolCapability::ReadOnly`. The read is in-scope for the capability label, but the *target* of the read is not the user expects `git_blame` to read files inside the workspace, not arbitrary paths on the host.</p>
<p>This is a sibling of the `git_show` argument-injection vulnerability filed separately, sharing the same root cause (missing `--end-of-options` sentinel and unvalidated `rev`).</p>
<p>## Impact</p>
<p>Arbitrary file read at the privilege of the user running DeepSeek-TUI, via malicious repository content combined with prompt injection (the t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c6mw-8xh8-gpq6"/>
  </entry>
</feed>
