<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 10:39:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-378302</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-378302</link>
      <description>EUVD-2026-378302</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-378302</guid>
    </item>
    <item>
      <title>fkie_cve-2026-102826</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-102826</link>
      <description>&lt;p&gt;simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path classification permits Git to load an attacker-controlled configuration file, and the initial remediation does not cover includeIf.&amp;lt;condition&amp;gt;.path, allowing the same file-loading primitive through a conditional include. A loaded configuration can set an executable Git option such as core.sshCommand, which Git invokes during the clone operation with the privileges of the Node.js process. Exploitation requires the application to pass attacker-influenced custom arguments and requires an attacker-controlled file that the process can read. This issue is fixed in 4.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path classification permits Git to load an attacker-controlled configuration file, and the initial remediation does not cover includeIf.&amp;lt;condition&amp;gt;.path, allowing the same file-loading primitive through a conditional include. A loaded configuration can set an executable Git option such as core.sshCommand, which Git invokes during the clone operation with the privileges of the Node.js process. Exploitation requires the application to pass attacker-influenced custom arguments and requires an attacker-controlled file that the process can read. This issue is fixed in 4.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-102826</guid>
    </item>
    <item>
      <title>GHSA-g4wm-2vf7-vfgr — simple-git allows command execution through unblocked Git configuration includes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g4wm-2vf7-vfgr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: simple-git&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An OS command injection vulnerability in `git.clone()` allows any application that flows attacker-influenced data into `customArgs` to execute arbitrary code. simple-git 3.36.0 (current latest on npm) ships without any `include.path` entry in the `blockUnsafeOperationsPlugin` denylist. Passing `-c include.path=&amp;lt;file&amp;gt;` via customArgs loads any local file as a gitconfig. The loaded file can set `core.sshCommand` (or any otherwise-denied key), and the next remote operation in the same clone executes the attacker&amp;#39;s command.&lt;/p&gt;
&lt;p&gt;PR #1167 (merged to main 2026-05-10, not yet released to npm) adds `preventConfigBuilder(&amp;#39;include.path&amp;#39;, &amp;#39;allowUnsafeInclude&amp;#39;)` to the denylist. The generated regex `/\s*include.path/` closes the plain spelling but does not match the conditional form `includeIf.&amp;lt;cond&amp;gt;.path`. The variant therefore survives the upcoming release if the regex is not tightened in the same cycle.&lt;/p&gt;
&lt;p&gt;This sits in the same denylist class as the prior incomplete-fix chain (CVE-2022-24433, CVE-2022-24066, CVE-2022-25912, CVE-2022-25860, CVE-2026-28291, CVE-2026-28292). `include` and `includeIf` are not referenced in any published advisory, in any commit prior to PR #1167, or anywhere in the 3.36.0 source.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Two sinks share the same root cause: the denylist is incomplete.&lt;/p&gt;
&lt;p&gt;### Sink A: published 3.36.0 has no `include.path` entry&lt;/p&gt;
&lt;p&gt;`packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts` in the v3.36.0 tag contains no entry for `include.path` or…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: simple-git&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An OS command injection vulnerability in `git.clone()` allows any application that flows attacker-influenced data into `customArgs` to execute arbitrary code. simple-git 3.36.0 (current latest on npm) ships without any `include.path` entry in the `blockUnsafeOperationsPlugin` denylist. Passing `-c include.path=&amp;lt;file&amp;gt;` via customArgs loads any local file as a gitconfig. The loaded file can set `core.sshCommand` (or any otherwise-denied key), and the next remote operation in the same clone executes the attacker&amp;#39;s command.&lt;/p&gt;
&lt;p&gt;PR #1167 (merged to main 2026-05-10, not yet released to npm) adds `preventConfigBuilder(&amp;#39;include.path&amp;#39;, &amp;#39;allowUnsafeInclude&amp;#39;)` to the denylist. The generated regex `/\s*include.path/` closes the plain spelling but does not match the conditional form `includeIf.&amp;lt;cond&amp;gt;.path`. The variant therefore survives the upcoming release if the regex is not tightened in the same cycle.&lt;/p&gt;
&lt;p&gt;This sits in the same denylist class as the prior incomplete-fix chain (CVE-2022-24433, CVE-2022-24066, CVE-2022-25912, CVE-2022-25860, CVE-2026-28291, CVE-2026-28292). `include` and `includeIf` are not referenced in any published advisory, in any commit prior to PR #1167, or anywhere in the 3.36.0 source.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Two sinks share the same root cause: the denylist is incomplete.&lt;/p&gt;
&lt;p&gt;### Sink A: published 3.36.0 has no `include.path` entry&lt;/p&gt;
&lt;p&gt;`packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts` in the v3.36.0 tag contains no entry for `include.path` or…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g4wm-2vf7-vfgr</guid>
    </item>
  </channel>
</rss>
