<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:23:26 +0000</lastBuildDate>
    <item>
      <title>BREW-aider-CVE-2026-78679 — GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (in…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-78679</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file&amp;#39;s contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f&amp;#39;s tag instance).&lt;/p&gt;
&lt;p&gt;## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = [&amp;#34;--file&amp;#34;,&amp;#34;-F&amp;#34;]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=&amp;#34;--file=&amp;lt;path&amp;gt;&amp;#34;` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file&amp;#39;s contents.&lt;/p&gt;
&lt;p&gt;## Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```python
from git import TagReference
t = TagReference.create(repo, &amp;#34;vpwn&amp;#34;, reference=&amp;#34;--file=/home/app/.ssh/id_rsa&amp;#34;)
print(t.tag.message)   # content…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file&amp;#39;s contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f&amp;#39;s tag instance).&lt;/p&gt;
&lt;p&gt;## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = [&amp;#34;--file&amp;#34;,&amp;#34;-F&amp;#34;]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=&amp;#34;--file=&amp;lt;path&amp;gt;&amp;#34;` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file&amp;#39;s contents.&lt;/p&gt;
&lt;p&gt;## Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```python
from git import TagReference
t = TagReference.create(repo, &amp;#34;vpwn&amp;#34;, reference=&amp;#34;--file=/home/app/.ssh/id_rsa&amp;#34;)
print(t.tag.message)   # content…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-78679</guid>
    </item>
    <item>
      <title>EUVD-2026-360020</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-360020</link>
      <description>EUVD-2026-360020</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-360020</guid>
    </item>
    <item>
      <title>fkie_cve-2026-78679</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78679</link>
      <description>&lt;p&gt;GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=&amp;lt;path&amp;gt; to read arbitrary files, with contents returned in the annotated tag message.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=&amp;lt;path&amp;gt; to read arbitrary files, with contents returned in the annotated tag message.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-78679</guid>
    </item>
    <item>
      <title>GHSA-3wxw-xv34-2frg — GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (in…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3wxw-xv34-2frg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: GitPython&lt;/p&gt;
&lt;p&gt;## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file&amp;#39;s contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f&amp;#39;s tag instance).&lt;/p&gt;
&lt;p&gt;## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = [&amp;#34;--file&amp;#34;,&amp;#34;-F&amp;#34;]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=&amp;#34;--file=&amp;lt;path&amp;gt;&amp;#34;` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file&amp;#39;s contents.&lt;/p&gt;
&lt;p&gt;## Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```python
from git import TagReference
t = TagReference.create(repo, &amp;#34;vpwn&amp;#34;, reference=&amp;#34;--file=/home/app/.ssh/id_rsa&amp;#34;)
print(t.tag.message)   # content…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: GitPython&lt;/p&gt;
&lt;p&gt;## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file&amp;#39;s contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f&amp;#39;s tag instance).&lt;/p&gt;
&lt;p&gt;## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = [&amp;#34;--file&amp;#34;,&amp;#34;-F&amp;#34;]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=&amp;#34;--file=&amp;lt;path&amp;gt;&amp;#34;` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file&amp;#39;s contents.&lt;/p&gt;
&lt;p&gt;## Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```python
from git import TagReference
t = TagReference.create(repo, &amp;#34;vpwn&amp;#34;, reference=&amp;#34;--file=/home/app/.ssh/id_rsa&amp;#34;)
print(t.tag.message)   # content…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3wxw-xv34-2frg</guid>
    </item>
    <item>
      <title>OESA-2026-3699 — python-GitPython security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3699</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-GitPython&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.(CVE-2026-73619)&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.(CVE-2026-73620)&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to &amp;amp;apos;git rev-list&amp;amp;apos; without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=&amp;amp;lt;path&amp;amp;gt;, causing &amp;amp;apos;git rev-list --output=&amp;amp;lt;path&amp;amp;gt;&amp;amp;apos; to open and truncate the target file to zero bytes before revision parsing. This allows destruction/blanking of an arbitrary file at the process&amp;amp;apos;s privilege level (no content control, 0-byte truncation).(CVE-2026-73621)&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.55 fails to disable env…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-GitPython&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.(CVE-2026-73619)&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.(CVE-2026-73620)&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to &amp;amp;apos;git rev-list&amp;amp;apos; without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=&amp;amp;lt;path&amp;amp;gt;, causing &amp;amp;apos;git rev-list --output=&amp;amp;lt;path&amp;amp;gt;&amp;amp;apos; to open and truncate the target file to zero bytes before revision parsing. This allows destruction/blanking of an arbitrary file at the process&amp;amp;apos;s privilege level (no content control, 0-byte truncation).(CVE-2026-73621)&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.55 fails to disable env…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3699</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11615-1 — python313-GitPython-3.1.59-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11615-1</link>
      <description>&lt;p&gt;python313-GitPython-3.1.59-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-GitPython-3.1.59-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11615-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3837 — GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (in…</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3837</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file&amp;#39;s contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f&amp;#39;s tag instance).&lt;/p&gt;
&lt;p&gt;## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = [&amp;#34;--file&amp;#34;,&amp;#34;-F&amp;#34;]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=&amp;#34;--file=&amp;lt;path&amp;gt;&amp;#34;` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file&amp;#39;s contents.&lt;/p&gt;
&lt;p&gt;## Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```python
from git import TagReference
t = TagReference.create(repo, &amp;#34;vpwn&amp;#34;, reference=&amp;#34;--file=/home/app/.ssh/id_rsa&amp;#34;)
print(t.tag.message)   # content…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file&amp;#39;s contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f&amp;#39;s tag instance).&lt;/p&gt;
&lt;p&gt;## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = [&amp;#34;--file&amp;#34;,&amp;#34;-F&amp;#34;]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=&amp;#34;--file=&amp;lt;path&amp;gt;&amp;#34;` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file&amp;#39;s contents.&lt;/p&gt;
&lt;p&gt;## Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```python
from git import TagReference
t = TagReference.create(repo, &amp;#34;vpwn&amp;#34;, reference=&amp;#34;--file=/home/app/.ssh/id_rsa&amp;#34;)
print(t.tag.message)   # content…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3837</guid>
    </item>
    <item>
      <title>RHSA-2026:59135 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:59135</link>
      <description>&lt;p&gt;django: Django: Remote code execution via GeoDjango spatial lookups aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens tmp: path Traversal via unsanitized prefix/postfix enables directory escape awxkit: path traversal via YAML !include directive pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Arbitrary Code Execution via Joined Short Options Bypass gitpython: GitPython: Command Injection via Git option prefix abbreviation aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses awx: project archive extraction allows path traversal file writes awx: webhook status callback SSRF leaks the Git PAT awx: notification backends allow SSRF and credential leakage gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding GitPython: GitPython: Arbitrary file read via TagReference.create()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;django: Django: Remote code execution via GeoDjango spatial lookups aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens tmp: path Traversal via unsanitized prefix/postfix enables directory escape awxkit: path traversal via YAML !include directive pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Arbitrary Code Execution via Joined Short Options Bypass gitpython: GitPython: Command Injection via Git option prefix abbreviation aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses awx: project archive extraction allows path traversal file writes awx: webhook status callback SSRF leaks the Git PAT awx: notification backends allow SSRF and credential leakage gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding GitPython: GitPython: Arbitrary file read via TagReference.create()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:59135</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3555 — Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</guid>
    </item>
  </channel>
</rss>
