<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:57:20 +0000</lastBuildDate>
    <item>
      <title>BREW-cloudflare-wrangler-CVE-2026-0933 — Wrangler affected by OS Command Injection in `wrangler pages deploy`</title>
      <link>https://cve.radiocsirt.org/vuln/brew-cloudflare-wrangler-cve-2026-0933</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: cloudflare-wrangler&lt;/p&gt;
&lt;p&gt;**Summary**&lt;/p&gt;
&lt;p&gt;A command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler.&lt;/p&gt;
&lt;p&gt;**Root cause**&lt;/p&gt;
&lt;p&gt;The `commitHash` variable, derived from user input via the `--commit-hash` CLI argument, is interpolated directly into a shell command using template literals (e.g., ``execSync(`git show -s --format=%B ${commitHash}`)``). Shell metacharacters are interpreted by the shell, enabling command execution.&lt;/p&gt;
&lt;p&gt;**Impact**&lt;/p&gt;
&lt;p&gt;This vulnerability is generally hard to exploit, as it requires `--commit-hash` to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the `--commit-hash` parameter is populated from external, potentially untrusted sources. An attacker could exploit this to:&lt;/p&gt;
&lt;p&gt;- Run any shell command.
- Exfiltrate environment variables.
- Compromise the CI runner to install backdoors or modify build artifacts.&lt;/p&gt;
&lt;p&gt;**Mitigation**&lt;/p&gt;
&lt;p&gt;- Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher. 
- Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher. 
- Users on Wrangler v2 (EOL) should upgrade to a supported major version.&lt;/p&gt;
&lt;p&gt;**Credits**&lt;/p&gt;
&lt;p&gt;Disclosed responsibly by kny4hacker.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: cloudflare-wrangler&lt;/p&gt;
&lt;p&gt;**Summary**&lt;/p&gt;
&lt;p&gt;A command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler.&lt;/p&gt;
&lt;p&gt;**Root cause**&lt;/p&gt;
&lt;p&gt;The `commitHash` variable, derived from user input via the `--commit-hash` CLI argument, is interpolated directly into a shell command using template literals (e.g., ``execSync(`git show -s --format=%B ${commitHash}`)``). Shell metacharacters are interpreted by the shell, enabling command execution.&lt;/p&gt;
&lt;p&gt;**Impact**&lt;/p&gt;
&lt;p&gt;This vulnerability is generally hard to exploit, as it requires `--commit-hash` to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the `--commit-hash` parameter is populated from external, potentially untrusted sources. An attacker could exploit this to:&lt;/p&gt;
&lt;p&gt;- Run any shell command.
- Exfiltrate environment variables.
- Compromise the CI runner to install backdoors or modify build artifacts.&lt;/p&gt;
&lt;p&gt;**Mitigation**&lt;/p&gt;
&lt;p&gt;- Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher. 
- Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher. 
- Users on Wrangler v2 (EOL) should upgrade to a supported major version.&lt;/p&gt;
&lt;p&gt;**Credits**&lt;/p&gt;
&lt;p&gt;Disclosed responsibly by kny4hacker.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-cloudflare-wrangler-cve-2026-0933</guid>
    </item>
    <item>
      <title>EUVD-2026-266523</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266523</link>
      <description>EUVD-2026-266523</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266523</guid>
    </item>
    <item>
      <title>fkie_cve-2026-0933</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-0933</link>
      <description>&lt;p&gt;SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler.&lt;/p&gt;
&lt;p&gt;Root causeThe commitHash variable, derived from user input via the --commit-hash CLI argument, is interpolated directly into a shell command using template literals (e.g.,  execSync(`git show -s --format=%B ${commitHash}`)). Shell metacharacters are interpreted by the shell, enabling command execution.&lt;/p&gt;
&lt;p&gt;ImpactThis vulnerability is generally hard to exploit, as it requires --commit-hash to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the&lt;/p&gt;
&lt;p&gt;--commit-hash parameter is populated from external, potentially untrusted sources. An attacker could exploit this to:&lt;/p&gt;
&lt;p&gt;*  Run any shell command.
  *  Exfiltrate environment variables.
  *  Compromise the CI runner to install backdoors or modify build artifacts.&lt;/p&gt;
&lt;p&gt;Credits Disclosed responsibly by kny4hacker.&lt;/p&gt;
&lt;p&gt;Mitigation
  *  Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher.
  *  Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher.
  *  Users on Wrangler v2 (EOL) should upgrade to a supported major version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler.&lt;/p&gt;
&lt;p&gt;Root causeThe commitHash variable, derived from user input via the --commit-hash CLI argument, is interpolated directly into a shell command using template literals (e.g.,  execSync(`git show -s --format=%B ${commitHash}`)). Shell metacharacters are interpreted by the shell, enabling command execution.&lt;/p&gt;
&lt;p&gt;ImpactThis vulnerability is generally hard to exploit, as it requires --commit-hash to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the&lt;/p&gt;
&lt;p&gt;--commit-hash parameter is populated from external, potentially untrusted sources. An attacker could exploit this to:&lt;/p&gt;
&lt;p&gt;*  Run any shell command.
  *  Exfiltrate environment variables.
  *  Compromise the CI runner to install backdoors or modify build artifacts.&lt;/p&gt;
&lt;p&gt;Credits Disclosed responsibly by kny4hacker.&lt;/p&gt;
&lt;p&gt;Mitigation
  *  Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher.
  *  Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher.
  *  Users on Wrangler v2 (EOL) should upgrade to a supported major version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-0933</guid>
    </item>
    <item>
      <title>GHSA-36p8-mvp6-cv38 — Wrangler affected by OS Command Injection in `wrangler pages deploy`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-36p8-mvp6-cv38</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: wrangler&lt;/p&gt;
&lt;p&gt;**Summary**&lt;/p&gt;
&lt;p&gt;A command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler.&lt;/p&gt;
&lt;p&gt;**Root cause**&lt;/p&gt;
&lt;p&gt;The `commitHash` variable, derived from user input via the `--commit-hash` CLI argument, is interpolated directly into a shell command using template literals (e.g., ``execSync(`git show -s --format=%B ${commitHash}`)``). Shell metacharacters are interpreted by the shell, enabling command execution.&lt;/p&gt;
&lt;p&gt;**Impact**&lt;/p&gt;
&lt;p&gt;This vulnerability is generally hard to exploit, as it requires `--commit-hash` to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the `--commit-hash` parameter is populated from external, potentially untrusted sources. An attacker could exploit this to:&lt;/p&gt;
&lt;p&gt;- Run any shell command.
- Exfiltrate environment variables.
- Compromise the CI runner to install backdoors or modify build artifacts.&lt;/p&gt;
&lt;p&gt;**Mitigation**&lt;/p&gt;
&lt;p&gt;- Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher. 
- Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher. 
- Users on Wrangler v2 (EOL) should upgrade to a supported major version.&lt;/p&gt;
&lt;p&gt;**Credits**&lt;/p&gt;
&lt;p&gt;Disclosed responsibly by kny4hacker.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: wrangler&lt;/p&gt;
&lt;p&gt;**Summary**&lt;/p&gt;
&lt;p&gt;A command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler.&lt;/p&gt;
&lt;p&gt;**Root cause**&lt;/p&gt;
&lt;p&gt;The `commitHash` variable, derived from user input via the `--commit-hash` CLI argument, is interpolated directly into a shell command using template literals (e.g., ``execSync(`git show -s --format=%B ${commitHash}`)``). Shell metacharacters are interpreted by the shell, enabling command execution.&lt;/p&gt;
&lt;p&gt;**Impact**&lt;/p&gt;
&lt;p&gt;This vulnerability is generally hard to exploit, as it requires `--commit-hash` to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the `--commit-hash` parameter is populated from external, potentially untrusted sources. An attacker could exploit this to:&lt;/p&gt;
&lt;p&gt;- Run any shell command.
- Exfiltrate environment variables.
- Compromise the CI runner to install backdoors or modify build artifacts.&lt;/p&gt;
&lt;p&gt;**Mitigation**&lt;/p&gt;
&lt;p&gt;- Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher. 
- Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher. 
- Users on Wrangler v2 (EOL) should upgrade to a supported major version.&lt;/p&gt;
&lt;p&gt;**Credits**&lt;/p&gt;
&lt;p&gt;Disclosed responsibly by kny4hacker.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-36p8-mvp6-cv38</guid>
    </item>
  </channel>
</rss>
