<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:21:34 +0000</lastBuildDate>
    <item>
      <title>BREW-git-annex-CVE-2018-10857 — git-annex private data exfiltration to compromised remote</title>
      <link>https://cve.radiocsirt.org/vuln/brew-git-annex-cve-2018-10857</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* private data exfiltration to compromised remote&lt;/p&gt;
&lt;p&gt;Some uses of git-annex were vulnerable to a private data exposure
and exfiltration attack. It could expose the content of files
located outside the *git-annex* repository, or content from a
private web server on localhost or the LAN.  Joey Hess discovered
this attack.&lt;/p&gt;
&lt;p&gt;To perform this attack, the attacker needs to have control over one
of the remotes of the victim&amp;#39;s *git-annex* repository. For example,
they may provide a public *git-annex* repository that the victim
clones. Or, equivalantly, the attacker could have read access to the
victim&amp;#39;s *git-annex* repository or a repository it pushes to, and
some channel to get commits into it (e.g. pull requests).&lt;/p&gt;
&lt;p&gt;These exploits are most likely to succeed when the victim is running
the `git-annex` assistant, or is periodically running `git annex
sync --content`.&lt;/p&gt;
&lt;p&gt;To perform the attack the attacker runs `git-annex addurl --relaxed
file:///etc/passwd` and commits this to the repository in some out
of the way place.  After the victim&amp;#39;s git repository receives that
change, `git-annex` follows the attacker-provided URL to the private
data, which it stores in the *git-annex* repository.  From there it
transfers the content to the remote *git-annex* repository that the
attacker has access to.&lt;/p&gt;
&lt;p&gt;As well as `file:///` URLs, the attacker can use URLs to private web
servers.  The URL can also be one that the attacker controls, that
redirects to a URL that is accessible to the victim…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* private data exfiltration to compromised remote&lt;/p&gt;
&lt;p&gt;Some uses of git-annex were vulnerable to a private data exposure
and exfiltration attack. It could expose the content of files
located outside the *git-annex* repository, or content from a
private web server on localhost or the LAN.  Joey Hess discovered
this attack.&lt;/p&gt;
&lt;p&gt;To perform this attack, the attacker needs to have control over one
of the remotes of the victim&amp;#39;s *git-annex* repository. For example,
they may provide a public *git-annex* repository that the victim
clones. Or, equivalantly, the attacker could have read access to the
victim&amp;#39;s *git-annex* repository or a repository it pushes to, and
some channel to get commits into it (e.g. pull requests).&lt;/p&gt;
&lt;p&gt;These exploits are most likely to succeed when the victim is running
the `git-annex` assistant, or is periodically running `git annex
sync --content`.&lt;/p&gt;
&lt;p&gt;To perform the attack the attacker runs `git-annex addurl --relaxed
file:///etc/passwd` and commits this to the repository in some out
of the way place.  After the victim&amp;#39;s git repository receives that
change, `git-annex` follows the attacker-provided URL to the private
data, which it stores in the *git-annex* repository.  From there it
transfers the content to the remote *git-annex* repository that the
attacker has access to.&lt;/p&gt;
&lt;p&gt;As well as `file:///` URLs, the attacker can use URLs to private web
servers.  The URL can also be one that the attacker controls, that
redirects to a URL that is accessible to the victim…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-git-annex-cve-2018-10857</guid>
    </item>
    <item>
      <title>cnvd-2018-13344</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-13344</link>
      <description>cnvd-2018-13344</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-13344</guid>
    </item>
    <item>
      <title>EUVD-2026-64847</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-64847</link>
      <description>EUVD-2026-64847</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-64847</guid>
    </item>
    <item>
      <title>fkie_cve-2018-10857</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-10857</link>
      <description>&lt;p&gt;git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-10857</guid>
    </item>
    <item>
      <title>GHSA-f7cm-x4r7-4852</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f7cm-x4r7-4852</link>
      <description>&lt;p&gt;git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f7cm-x4r7-4852</guid>
    </item>
    <item>
      <title>gsd-2018-10857</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-10857</link>
      <description>gsd-2018-10857</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-10857</guid>
    </item>
    <item>
      <title>HSEC-2023-0010 — git-annex private data exfiltration to compromised remote</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0010</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* private data exfiltration to compromised remote&lt;/p&gt;
&lt;p&gt;Some uses of git-annex were vulnerable to a private data exposure
and exfiltration attack. It could expose the content of files
located outside the *git-annex* repository, or content from a
private web server on localhost or the LAN.  Joey Hess discovered
this attack.&lt;/p&gt;
&lt;p&gt;To perform this attack, the attacker needs to have control over one
of the remotes of the victim&amp;#39;s *git-annex* repository. For example,
they may provide a public *git-annex* repository that the victim
clones. Or, equivalantly, the attacker could have read access to the
victim&amp;#39;s *git-annex* repository or a repository it pushes to, and
some channel to get commits into it (e.g. pull requests).&lt;/p&gt;
&lt;p&gt;These exploits are most likely to succeed when the victim is running
the `git-annex` assistant, or is periodically running `git annex
sync --content`.&lt;/p&gt;
&lt;p&gt;To perform the attack the attacker runs `git-annex addurl --relaxed
file:///etc/passwd` and commits this to the repository in some out
of the way place.  After the victim&amp;#39;s git repository receives that
change, `git-annex` follows the attacker-provided URL to the private
data, which it stores in the *git-annex* repository.  From there it
transfers the content to the remote *git-annex* repository that the
attacker has access to.&lt;/p&gt;
&lt;p&gt;As well as `file:///` URLs, the attacker can use URLs to private web
servers.  The URL can also be one that the attacker controls, that
redirects to a URL that is accessible to the victim…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* private data exfiltration to compromised remote&lt;/p&gt;
&lt;p&gt;Some uses of git-annex were vulnerable to a private data exposure
and exfiltration attack. It could expose the content of files
located outside the *git-annex* repository, or content from a
private web server on localhost or the LAN.  Joey Hess discovered
this attack.&lt;/p&gt;
&lt;p&gt;To perform this attack, the attacker needs to have control over one
of the remotes of the victim&amp;#39;s *git-annex* repository. For example,
they may provide a public *git-annex* repository that the victim
clones. Or, equivalantly, the attacker could have read access to the
victim&amp;#39;s *git-annex* repository or a repository it pushes to, and
some channel to get commits into it (e.g. pull requests).&lt;/p&gt;
&lt;p&gt;These exploits are most likely to succeed when the victim is running
the `git-annex` assistant, or is periodically running `git annex
sync --content`.&lt;/p&gt;
&lt;p&gt;To perform the attack the attacker runs `git-annex addurl --relaxed
file:///etc/passwd` and commits this to the repository in some out
of the way place.  After the victim&amp;#39;s git repository receives that
change, `git-annex` follows the attacker-provided URL to the private
data, which it stores in the *git-annex* repository.  From there it
transfers the content to the remote *git-annex* repository that the
attacker has access to.&lt;/p&gt;
&lt;p&gt;As well as `file:///` URLs, the attacker can use URLs to private web
servers.  The URL can also be one that the attacker controls, that
redirects to a URL that is accessible to the victim…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0010</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-10857</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-10857</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: git-annex, Ubuntu:18.04:LTS: git-annex&lt;/p&gt;
&lt;p&gt;git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: git-annex, Ubuntu:18.04:LTS: git-annex&lt;/p&gt;
&lt;p&gt;git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-10857</guid>
    </item>
  </channel>
</rss>
