<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:02:28 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10827</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10827</link>
      <description>bdu:2026-10827</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10827</guid>
    </item>
    <item>
      <title>BREW-aider-CVE-2026-44243 — GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the rep…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-44243</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;## 🧾 Summary&lt;/p&gt;
&lt;p&gt;A vulnerability in **GitPython** allows **attackers who can supply a crafted reference path to an application using GitPython** to **write, overwrite, move, or delete files outside the repository’s `.git` directory** via **insufficient validation of reference paths in reference creation, rename, and delete operations**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 📦 Affected Versions&lt;/p&gt;
&lt;p&gt;* Affected: `&amp;lt;= 3.1.46` and current `main` (`3.1.47` in local checkout)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 🧠 Details&lt;/p&gt;
&lt;p&gt;### Vulnerability Type&lt;/p&gt;
&lt;p&gt;**Path Traversal leading to Arbitrary File Write and Arbitrary File Deletion**&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;Reference paths are validated when they are resolved for reading, but are not consistently validated before filesystem write, rename, and delete operations.&lt;/p&gt;
&lt;p&gt;`SymbolicReference._check_ref_name_valid()` rejects traversal sequences such as `..`, but `SymbolicReference.create`, `Reference.create`, `SymbolicReference.set_reference`, `SymbolicReference.rename`, and `SymbolicReference.delete` still construct filesystem paths from attacker-controlled ref names without enforcing repository boundaries.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;```python
def set_reference(self, ref, logmsg=None):
    ...
    fpath = self.abspath
    assure_directory_exists(fpath, is_file=True)&lt;/p&gt;
&lt;p&gt;lfd = LockedFD(fpath)
    fd = lfd.open(write=True, stream=True)
    ...
```&lt;/p&gt;
&lt;p&gt;```python
@classmethod
def delete(cls, repo, path):
    full_ref_path = cls.to_full_path(path)
    abs_path = os.path.join(repo.common_dir, full_ref_path)
    if os.path.exis…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;## 🧾 Summary&lt;/p&gt;
&lt;p&gt;A vulnerability in **GitPython** allows **attackers who can supply a crafted reference path to an application using GitPython** to **write, overwrite, move, or delete files outside the repository’s `.git` directory** via **insufficient validation of reference paths in reference creation, rename, and delete operations**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 📦 Affected Versions&lt;/p&gt;
&lt;p&gt;* Affected: `&amp;lt;= 3.1.46` and current `main` (`3.1.47` in local checkout)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 🧠 Details&lt;/p&gt;
&lt;p&gt;### Vulnerability Type&lt;/p&gt;
&lt;p&gt;**Path Traversal leading to Arbitrary File Write and Arbitrary File Deletion**&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;Reference paths are validated when they are resolved for reading, but are not consistently validated before filesystem write, rename, and delete operations.&lt;/p&gt;
&lt;p&gt;`SymbolicReference._check_ref_name_valid()` rejects traversal sequences such as `..`, but `SymbolicReference.create`, `Reference.create`, `SymbolicReference.set_reference`, `SymbolicReference.rename`, and `SymbolicReference.delete` still construct filesystem paths from attacker-controlled ref names without enforcing repository boundaries.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;```python
def set_reference(self, ref, logmsg=None):
    ...
    fpath = self.abspath
    assure_directory_exists(fpath, is_file=True)&lt;/p&gt;
&lt;p&gt;lfd = LockedFD(fpath)
    fd = lfd.open(write=True, stream=True)
    ...
```&lt;/p&gt;
&lt;p&gt;```python
@classmethod
def delete(cls, repo, path):
    full_ref_path = cls.to_full_path(path)
    abs_path = os.path.join(repo.common_dir, full_ref_path)
    if os.path.exis…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-44243</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1056 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1056</link>
      <description>certfr-2026-avi-1056</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1056</guid>
    </item>
    <item>
      <title>EUVD-2026-309080</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-309080</link>
      <description>EUVD-2026-309080</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-309080</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44243</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44243</link>
      <description>&lt;p&gt;GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44243</guid>
    </item>
    <item>
      <title>GHSA-7545-fcxq-7j24 — GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the rep…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7545-fcxq-7j24</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: GitPython&lt;/p&gt;
&lt;p&gt;## 🧾 Summary&lt;/p&gt;
&lt;p&gt;A vulnerability in **GitPython** allows **attackers who can supply a crafted reference path to an application using GitPython** to **write, overwrite, move, or delete files outside the repository’s `.git` directory** via **insufficient validation of reference paths in reference creation, rename, and delete operations**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 📦 Affected Versions&lt;/p&gt;
&lt;p&gt;* Affected: `&amp;lt;= 3.1.46` and current `main` (`3.1.47` in local checkout)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 🧠 Details&lt;/p&gt;
&lt;p&gt;### Vulnerability Type&lt;/p&gt;
&lt;p&gt;**Path Traversal leading to Arbitrary File Write and Arbitrary File Deletion**&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;Reference paths are validated when they are resolved for reading, but are not consistently validated before filesystem write, rename, and delete operations.&lt;/p&gt;
&lt;p&gt;`SymbolicReference._check_ref_name_valid()` rejects traversal sequences such as `..`, but `SymbolicReference.create`, `Reference.create`, `SymbolicReference.set_reference`, `SymbolicReference.rename`, and `SymbolicReference.delete` still construct filesystem paths from attacker-controlled ref names without enforcing repository boundaries.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;```python
def set_reference(self, ref, logmsg=None):
    ...
    fpath = self.abspath
    assure_directory_exists(fpath, is_file=True)&lt;/p&gt;
&lt;p&gt;lfd = LockedFD(fpath)
    fd = lfd.open(write=True, stream=True)
    ...
```&lt;/p&gt;
&lt;p&gt;```python
@classmethod
def delete(cls, repo, path):
    full_ref_path = cls.to_full_path(path)
    abs_path = os.path.join(repo.common_dir, full_ref_path)
    if os.path.exis…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: GitPython&lt;/p&gt;
&lt;p&gt;## 🧾 Summary&lt;/p&gt;
&lt;p&gt;A vulnerability in **GitPython** allows **attackers who can supply a crafted reference path to an application using GitPython** to **write, overwrite, move, or delete files outside the repository’s `.git` directory** via **insufficient validation of reference paths in reference creation, rename, and delete operations**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 📦 Affected Versions&lt;/p&gt;
&lt;p&gt;* Affected: `&amp;lt;= 3.1.46` and current `main` (`3.1.47` in local checkout)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 🧠 Details&lt;/p&gt;
&lt;p&gt;### Vulnerability Type&lt;/p&gt;
&lt;p&gt;**Path Traversal leading to Arbitrary File Write and Arbitrary File Deletion**&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;Reference paths are validated when they are resolved for reading, but are not consistently validated before filesystem write, rename, and delete operations.&lt;/p&gt;
&lt;p&gt;`SymbolicReference._check_ref_name_valid()` rejects traversal sequences such as `..`, but `SymbolicReference.create`, `Reference.create`, `SymbolicReference.set_reference`, `SymbolicReference.rename`, and `SymbolicReference.delete` still construct filesystem paths from attacker-controlled ref names without enforcing repository boundaries.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;```python
def set_reference(self, ref, logmsg=None):
    ...
    fpath = self.abspath
    assure_directory_exists(fpath, is_file=True)&lt;/p&gt;
&lt;p&gt;lfd = LockedFD(fpath)
    fd = lfd.open(write=True, stream=True)
    ...
```&lt;/p&gt;
&lt;p&gt;```python
@classmethod
def delete(cls, repo, path):
    full_ref_path = cls.to_full_path(path)
    abs_path = os.path.join(repo.common_dir, full_ref_path)
    if os.path.exis…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7545-fcxq-7j24</guid>
    </item>
    <item>
      <title>OESA-2026-2306 — python-GitPython security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2306</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-GitPython&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;### Summary
GitPython blocks dangerous Git options such as `--upload-pack` and `--receive-pack` by default, but the equivalent Python kwargs `upload_pack` and `receive_pack` bypass that check. If an application passes attacker-controlled kwargs into `Repo.clone_from()`, `Remote.fetch()`, `Remote.pull()`, or `Remote.push()`, this leads to arbitrary command execution even when `allow_unsafe_options` is left at its default value of `False`.&lt;/p&gt;
&lt;p&gt;### Details
GitPython explicitly treats helper-command options as unsafe because they can be used to execute arbitrary commands:&lt;/p&gt;
&lt;p&gt;- `git/repo/base.py:145-153` marks clone options such as `--upload-pack`, `-u`, `--config`, and `-c` as unsafe.
- `git/remote.py:535-548` marks fetch/pull/push options such as `--upload-pack`, `--receive-pack`, and `--exec` as unsafe.&lt;/p&gt;
&lt;p&gt;The vulnerable API paths check the raw kwarg names before they&amp;amp;apos;re its normalized into command-line flags:&lt;/p&gt;
&lt;p&gt;- `Repo.clone_from()` checks `list(kwargs.keys())` in `git/repo/base.py:1387-1390`
- `Remote.fetch()` checks `list(kwargs.keys())` in `git/remote.py:1070-1071`
- `Remote.pull()` checks `list(kwargs.keys())` in `git/remote.py:1124-1125`
- `Remote.push()` checks `list(kwargs.keys())` in `git/remote.py:1197-1198`&lt;/p&gt;
&lt;p&gt;That validation is performed by `Git.check_unsafe_options()` in `git/cmd.py:948-961`. The validator correctly…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-GitPython&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;### Summary
GitPython blocks dangerous Git options such as `--upload-pack` and `--receive-pack` by default, but the equivalent Python kwargs `upload_pack` and `receive_pack` bypass that check. If an application passes attacker-controlled kwargs into `Repo.clone_from()`, `Remote.fetch()`, `Remote.pull()`, or `Remote.push()`, this leads to arbitrary command execution even when `allow_unsafe_options` is left at its default value of `False`.&lt;/p&gt;
&lt;p&gt;### Details
GitPython explicitly treats helper-command options as unsafe because they can be used to execute arbitrary commands:&lt;/p&gt;
&lt;p&gt;- `git/repo/base.py:145-153` marks clone options such as `--upload-pack`, `-u`, `--config`, and `-c` as unsafe.
- `git/remote.py:535-548` marks fetch/pull/push options such as `--upload-pack`, `--receive-pack`, and `--exec` as unsafe.&lt;/p&gt;
&lt;p&gt;The vulnerable API paths check the raw kwarg names before they&amp;amp;apos;re its normalized into command-line flags:&lt;/p&gt;
&lt;p&gt;- `Repo.clone_from()` checks `list(kwargs.keys())` in `git/repo/base.py:1387-1390`
- `Remote.fetch()` checks `list(kwargs.keys())` in `git/remote.py:1070-1071`
- `Remote.pull()` checks `list(kwargs.keys())` in `git/remote.py:1124-1125`
- `Remote.push()` checks `list(kwargs.keys())` in `git/remote.py:1197-1198`&lt;/p&gt;
&lt;p&gt;That validation is performed by `Git.check_unsafe_options()` in `git/cmd.py:948-961`. The validator correctly…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2306</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10758-1 — python311-GitPython-3.1.49-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10758-1</link>
      <description>&lt;p&gt;python311-GitPython-3.1.49-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-GitPython-3.1.49-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10758-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2162</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2162</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2162</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21813-1 — Security update for python-GitPython</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21813-1</link>
      <description>&lt;p&gt;Security update for python-GitPython&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-GitPython&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21813-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-44243</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44243</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:Pro:24.04:LTS: python-git, Ubuntu:25.10: python-git, Ubuntu:Pro:26.04:LTS: python-git&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:Pro:24.04:LTS: python-git, Ubuntu:25.10: python-git, Ubuntu:Pro:26.04:LTS: python-git&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44243</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2933 — Splunk SOAR: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</guid>
    </item>
  </channel>
</rss>
