<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 09:50:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265575</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265575</link>
      <description>EUVD-2026-265575</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265575</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22798</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22798</link>
      <description>&lt;p&gt;hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options under the -O argument. These have been logged in raw form. If users provide sensitive data such as API tokens (e.g., via hermes deposit -O invenio_rdm.auth_token SECRET), these are written to the log file in plain text, making them available to whoever can access the log file. This vulnerability is fixed in 0.9.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options under the -O argument. These have been logged in raw form. If users provide sensitive data such as API tokens (e.g., via hermes deposit -O invenio_rdm.auth_token SECRET), these are written to the log file in plain text, making them available to whoever can access the log file. This vulnerability is fixed in 0.9.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22798</guid>
    </item>
    <item>
      <title>GHSA-jm5j-jfrm-hm23 — hermes's raw options logging may disclose secrets passed in via subcommand options argument</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jm5j-jfrm-hm23</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: hermes&lt;/p&gt;
&lt;p&gt;Thanks, @thunze for reporting this!&lt;/p&gt;
&lt;p&gt;`hermes` subcommands take arbitrary options under the `-O` argument. These have been logged in raw form since https://github.com/softwarepub/hermes/commit/7f64f102e916c76dc44404b77ab2a80f5a4e59b1 in: https://github.com/softwarepub/hermes/blob/3a92f42b2b976fdbc2c49a621de6d665364a7cee/src/hermes/commands/cli.py#L66&lt;/p&gt;
&lt;p&gt;If users provide sensitive data such as API tokens (e.g., via `hermes deposit -O invenio_rdm.auth_token SECRET`), these are written to the log file in plain text, making them available to whoever can access the log file.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;As currently, `hermes.log` is not yet uploaded automatically as an artifact in CI, this vuln impacts:&lt;/p&gt;
&lt;p&gt;- local users working on shared access computers, where logs may be written to a commonly accessible file system
- CI users whose CI logs are accessible to others, e.g., through group or organization rights&lt;/p&gt;
&lt;p&gt;Potentially, if the changes merged from https://github.com/softwarepub/ci-templates/pull/13 are merged into `ci-templates` via https://github.com/softwarepub/ci-templates/pull/14, this would automate the disclosure of Invenio auth tokens at least for all CI runs against Invenio instances!&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been patched in [`hermes` 0.9.1](TODO) by masking all values passed using `-O`.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Upgrade to `hermes` &amp;gt;= 0.9.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: hermes&lt;/p&gt;
&lt;p&gt;Thanks, @thunze for reporting this!&lt;/p&gt;
&lt;p&gt;`hermes` subcommands take arbitrary options under the `-O` argument. These have been logged in raw form since https://github.com/softwarepub/hermes/commit/7f64f102e916c76dc44404b77ab2a80f5a4e59b1 in: https://github.com/softwarepub/hermes/blob/3a92f42b2b976fdbc2c49a621de6d665364a7cee/src/hermes/commands/cli.py#L66&lt;/p&gt;
&lt;p&gt;If users provide sensitive data such as API tokens (e.g., via `hermes deposit -O invenio_rdm.auth_token SECRET`), these are written to the log file in plain text, making them available to whoever can access the log file.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;As currently, `hermes.log` is not yet uploaded automatically as an artifact in CI, this vuln impacts:&lt;/p&gt;
&lt;p&gt;- local users working on shared access computers, where logs may be written to a commonly accessible file system
- CI users whose CI logs are accessible to others, e.g., through group or organization rights&lt;/p&gt;
&lt;p&gt;Potentially, if the changes merged from https://github.com/softwarepub/ci-templates/pull/13 are merged into `ci-templates` via https://github.com/softwarepub/ci-templates/pull/14, this would automate the disclosure of Invenio auth tokens at least for all CI runs against Invenio instances!&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been patched in [`hermes` 0.9.1](TODO) by masking all values passed using `-O`.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Upgrade to `hermes` &amp;gt;= 0.9.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jm5j-jfrm-hm23</guid>
    </item>
    <item>
      <title>PYSEC-2026-1449 — hermes's raw options logging may disclose secrets passed in via subcommand options argument</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1449</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: hermes&lt;/p&gt;
&lt;p&gt;Thanks, @thunze for reporting this!&lt;/p&gt;
&lt;p&gt;`hermes` subcommands take arbitrary options under the `-O` argument. These have been logged in raw form since https://github.com/softwarepub/hermes/commit/7f64f102e916c76dc44404b77ab2a80f5a4e59b1 in: https://github.com/softwarepub/hermes/blob/3a92f42b2b976fdbc2c49a621de6d665364a7cee/src/hermes/commands/cli.py#L66&lt;/p&gt;
&lt;p&gt;If users provide sensitive data such as API tokens (e.g., via `hermes deposit -O invenio_rdm.auth_token SECRET`), these are written to the log file in plain text, making them available to whoever can access the log file.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;As currently, `hermes.log` is not yet uploaded automatically as an artifact in CI, this vuln impacts:&lt;/p&gt;
&lt;p&gt;- local users working on shared access computers, where logs may be written to a commonly accessible file system
- CI users whose CI logs are accessible to others, e.g., through group or organization rights&lt;/p&gt;
&lt;p&gt;Potentially, if the changes merged from https://github.com/softwarepub/ci-templates/pull/13 are merged into `ci-templates` via https://github.com/softwarepub/ci-templates/pull/14, this would automate the disclosure of Invenio auth tokens at least for all CI runs against Invenio instances!&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been patched in [`hermes` 0.9.1](TODO) by masking all values passed using `-O`.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Upgrade to `hermes` &amp;gt;= 0.9.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: hermes&lt;/p&gt;
&lt;p&gt;Thanks, @thunze for reporting this!&lt;/p&gt;
&lt;p&gt;`hermes` subcommands take arbitrary options under the `-O` argument. These have been logged in raw form since https://github.com/softwarepub/hermes/commit/7f64f102e916c76dc44404b77ab2a80f5a4e59b1 in: https://github.com/softwarepub/hermes/blob/3a92f42b2b976fdbc2c49a621de6d665364a7cee/src/hermes/commands/cli.py#L66&lt;/p&gt;
&lt;p&gt;If users provide sensitive data such as API tokens (e.g., via `hermes deposit -O invenio_rdm.auth_token SECRET`), these are written to the log file in plain text, making them available to whoever can access the log file.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;As currently, `hermes.log` is not yet uploaded automatically as an artifact in CI, this vuln impacts:&lt;/p&gt;
&lt;p&gt;- local users working on shared access computers, where logs may be written to a commonly accessible file system
- CI users whose CI logs are accessible to others, e.g., through group or organization rights&lt;/p&gt;
&lt;p&gt;Potentially, if the changes merged from https://github.com/softwarepub/ci-templates/pull/13 are merged into `ci-templates` via https://github.com/softwarepub/ci-templates/pull/14, this would automate the disclosure of Invenio auth tokens at least for all CI runs against Invenio instances!&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been patched in [`hermes` 0.9.1](TODO) by masking all values passed using `-O`.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Upgrade to `hermes` &amp;gt;= 0.9.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1449</guid>
    </item>
  </channel>
</rss>
