<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:13:38.357478+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-git-annex-cve-2018-10857</id>
    <title>BREW-git-annex-CVE-2018-10857 — git-annex private data exfiltration to compromised remote</title>
    <updated>2026-10-02T16:13:38.359639+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: git-annex</p>
<p># *git-annex* private data exfiltration to compromised remote</p>
<p>Some uses of git-annex were vulnerable to a private data exposure
and exfiltration attack. It could expose the content of files
located outside the *git-annex* repository, or content from a
private web server on localhost or the LAN.  Joey Hess discovered
this attack.</p>
<p>To perform this attack, the attacker needs to have control over one
of the remotes of the victim's *git-annex* repository. For example,
they may provide a public *git-annex* repository that the victim
clones. Or, equivalantly, the attacker could have read access to the
victim's *git-annex* repository or a repository it pushes to, and
some channel to get commits into it (e.g. pull requests).</p>
<p>These exploits are most likely to succeed when the victim is running
the `git-annex` assistant, or is periodically running `git annex
sync --content`.</p>
<p>To perform the attack the attacker runs `git-annex addurl --relaxed
file:///etc/passwd` and commits this to the repository in some out
of the way place.  After the victim's git repository receives that
change, `git-annex` follows the attacker-provided URL to the private
data, which it stores in the *git-annex* repository.  From there it
transfers the content to the remote *git-annex* repository that the
attacker has access to.</p>
<p>As well as `file:///` URLs, the attacker can use URLs to private web
servers.  The URL can also be one that the attacker controls, that
redirects to a URL that is accessible to the victim…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-git-annex-cve-2018-10857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2018-10857</id>
    <title>CVE-2018-10857</title>
    <updated>2026-10-02T16:13:38.359708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> [UNKNOWN] git-annex</p>
<p>git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2018-10857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/hsec-2023-0011</id>
    <title>HSEC-2023-0011 — git-annex GPG decryption attack via compromised remote</title>
    <updated>2026-10-02T16:13:38.359736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Hackage: git-annex</p>
<p># *git-annex* GPG decryption attack via compromised remote</p>
<p>A malicious server for a special remote could trick `git-annex` into
decrypting a file that was encrypted to the user's GPG key.  This
attack could be used to expose encrypted data that was never stored
in *git-annex*.  Daniel Dent discovered this attack in collaboration
with Joey Hess.</p>
<p>To perform this attack the attacker needs control of a server
hosting an *encrypted* special remote used by the victim's
*git-annex* repository.  The attacker uses `git annex addurl
--relaxed` with an innocuous URL, and waits for the user's
`git-annex` to download it, and upload an (encrypted) copy to the
special remote they also control.  At some later point, when the
user downloads the content from the special remote, the attacker
instead sends them the content of the GPG-encrypted file that they
wish to have decrypted in its place (which may have been exfiltrated
from the victim's system via the attack described in
**HSEC-2023-0010** / **CVE-2018-10857**, or acquired by other
means).  Finally, the attacker drops their own copy of the original
innocuous URL, and waits for the victim `git-annex` to send them the
accidentially decrypted file.</p>
<p>The issue was fixed by making `git-annex` refuse to download
encrypted content from special remotes, unless it knows the hash of
the expected content.  When the attacker provides some other
GPG-encrypted content, it will fail the hash check and be discarded.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/hsec-2023-0011"/>
  </entry>
</feed>
