<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 04:22:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-359379</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-359379</link>
      <description>EUVD-2026-359379</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-359379</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71493</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71493</link>
      <description>&lt;p&gt;Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPaths template functions in internal/config/template/parser.go use a lexical filepath.Rel check and a leaf-only os.Lstat check that do not resolve an intermediate directory symlink. A repository can contain a path such as evil/file where evil points outside the checkout, causing os.ReadFile and related operations to follow the symlink and read runner-accessible files. The resulting content is rendered into generated configuration and can be surfaced through the Infracost dashboard or pull request comment, with greater impact in workflows that provide repository secrets. This issue is fixed in version 0.10.45.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPaths template functions in internal/config/template/parser.go use a lexical filepath.Rel check and a leaf-only os.Lstat check that do not resolve an intermediate directory symlink. A repository can contain a path such as evil/file where evil points outside the checkout, causing os.ReadFile and related operations to follow the symlink and read runner-accessible files. The resulting content is rendered into generated configuration and can be surfaced through the Infracost dashboard or pull request comment, with greater impact in workflows that provide repository secrets. This issue is fixed in version 0.10.45.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71493</guid>
    </item>
    <item>
      <title>GHSA-mmg6-4qmv-6pc8 — Infracost: Arbitrary file read via config-template readFile symlink traversal</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mmg6-4qmv-6pc8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/infracost/infracost&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Path traversal via link following in the Infracost config-template parser. The `readFile`, `pathExists`, `isDir`, and `matchPaths` template functions confined repo-supplied paths with a lexical `filepath.Rel` check plus a leaf-only `os.Lstat`:&lt;/p&gt;
&lt;p&gt;```
{{ readFile &amp;#34;evil/file&amp;#34; }}
```&lt;/p&gt;
&lt;p&gt;With an intermediate directory symlink committed in the repo (`evil -&amp;gt; /`), the path is lexically clean and the leaf is a regular file, so both checks pass, but `os.ReadFile` follows the symlink and reads outside the checkout. The contents are rendered into the generated config and surfaced via the Infracost dashboard and PR comment, so anyone who can open a pull request can read files off the runner.&lt;/p&gt;
&lt;p&gt;Affects `infracost` up to and including `v0.10.44`. Successful exploitation reads any file the CLI process can reach on the runner. Impact depends on what the run exposes: under `on: pull_request` (the configuration in Infracost&amp;#39;s documentation) fork pull requests run without secrets and with a read-only token, so exposure is limited. If Infracost runs under `pull_request_target`, or is triggered by a same-repository pull request, the read reaches the repository&amp;#39;s secrets, enabling secret theft. The patch confines all four functions regardless of trigger.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in `v0.10.45` ([#3586](https://github.com/infracost/infracost/pull/3586)) by routing all four functions through `security.IsPathAllowed`, which resolves symlinks anywhere in the path before a segment-aware containment…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/infracost/infracost&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Path traversal via link following in the Infracost config-template parser. The `readFile`, `pathExists`, `isDir`, and `matchPaths` template functions confined repo-supplied paths with a lexical `filepath.Rel` check plus a leaf-only `os.Lstat`:&lt;/p&gt;
&lt;p&gt;```
{{ readFile &amp;#34;evil/file&amp;#34; }}
```&lt;/p&gt;
&lt;p&gt;With an intermediate directory symlink committed in the repo (`evil -&amp;gt; /`), the path is lexically clean and the leaf is a regular file, so both checks pass, but `os.ReadFile` follows the symlink and reads outside the checkout. The contents are rendered into the generated config and surfaced via the Infracost dashboard and PR comment, so anyone who can open a pull request can read files off the runner.&lt;/p&gt;
&lt;p&gt;Affects `infracost` up to and including `v0.10.44`. Successful exploitation reads any file the CLI process can reach on the runner. Impact depends on what the run exposes: under `on: pull_request` (the configuration in Infracost&amp;#39;s documentation) fork pull requests run without secrets and with a read-only token, so exposure is limited. If Infracost runs under `pull_request_target`, or is triggered by a same-repository pull request, the read reaches the repository&amp;#39;s secrets, enabling secret theft. The patch confines all four functions regardless of trigger.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in `v0.10.45` ([#3586](https://github.com/infracost/infracost/pull/3586)) by routing all four functions through `security.IsPathAllowed`, which resolves symlinks anywhere in the path before a segment-aware containment…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mmg6-4qmv-6pc8</guid>
    </item>
  </channel>
</rss>
