<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:34:01 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-355074</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355074</link>
      <description>EUVD-2026-355074</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355074</guid>
    </item>
    <item>
      <title>fkie_cve-2026-75913</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-75913</link>
      <description>&lt;p&gt;CodeWhale (codewhale / codewhale-tui) versions &amp;gt;= 0.8.41 and &amp;lt; 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag. Because the tool is registered as auto-approved and advertised as read-only, an attacker (via a malicious repository combined with prompt injection) can cause an unprompted arbitrary file write at the privilege of the invoking user, targeting sensitive files such as ~/.ssh/authorized_keys, ~/.bashrc, or ~/.gitconfig. Fixed in 0.8.64 by adding rev validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CodeWhale (codewhale / codewhale-tui) versions &amp;gt;= 0.8.41 and &amp;lt; 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag. Because the tool is registered as auto-approved and advertised as read-only, an attacker (via a malicious repository combined with prompt injection) can cause an unprompted arbitrary file write at the privilege of the invoking user, targeting sensitive files such as ~/.ssh/authorized_keys, ~/.bashrc, or ~/.gitconfig. Fixed in 0.8.64 by adding rev validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-75913</guid>
    </item>
    <item>
      <title>GHSA-7j5w-7r7x-9v27 — CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7j5w-7r7x-9v27</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: deepseek-tui, npm: deepseek-tui, crates.io: codewhale-tui, npm: codewhale&lt;/p&gt;
&lt;p&gt;### Maintainer resolution&lt;/p&gt;
&lt;p&gt;The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below.&lt;/p&gt;
&lt;p&gt;# Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;The `git_show` tool in DeepSeek-TUI executes `git show` with the model-supplied `rev` parameter passed unvalidated into the argv. `git show` honours the `--output=&amp;lt;path&amp;gt;` option, so a `rev` value beginning with `--output=` is interpreted as a flag rather than a revision. The tool is registered with `ApprovalRequirement::Auto` and declares `ToolCapability::ReadOnly`, so the write happens without a user prompt and contradicts the capability the catalog advertises to the model and the user.&lt;/p&gt;
&lt;p&gt;This is the same vulnerability class as GHSA-72w5-pf8h-xfp4 (CVE-2026-45374): an auto-approved tool produces an effect outside the boundary the user consented to.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A malicious repository combined with prompt injection, the threat model already documented in CVE-2026-45311 (auto-loaded `AGENTS.md` is treated as instructions by the model) yields an unprompted arbitrary file write at the privilege of the user running DeepSeek-TUI.&lt;/p&gt;
&lt;p&gt;Useful targets reachable as the invoking user:&lt;/p&gt;
&lt;p&gt;- `~/.ssh/authorized_keys`
- `~/.bashrc`, `~/.zshrc`, `~/.profile`
- `~/.gitconfig` (chainable…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: deepseek-tui, npm: deepseek-tui, crates.io: codewhale-tui, npm: codewhale&lt;/p&gt;
&lt;p&gt;### Maintainer resolution&lt;/p&gt;
&lt;p&gt;The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below.&lt;/p&gt;
&lt;p&gt;# Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;The `git_show` tool in DeepSeek-TUI executes `git show` with the model-supplied `rev` parameter passed unvalidated into the argv. `git show` honours the `--output=&amp;lt;path&amp;gt;` option, so a `rev` value beginning with `--output=` is interpreted as a flag rather than a revision. The tool is registered with `ApprovalRequirement::Auto` and declares `ToolCapability::ReadOnly`, so the write happens without a user prompt and contradicts the capability the catalog advertises to the model and the user.&lt;/p&gt;
&lt;p&gt;This is the same vulnerability class as GHSA-72w5-pf8h-xfp4 (CVE-2026-45374): an auto-approved tool produces an effect outside the boundary the user consented to.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A malicious repository combined with prompt injection, the threat model already documented in CVE-2026-45311 (auto-loaded `AGENTS.md` is treated as instructions by the model) yields an unprompted arbitrary file write at the privilege of the user running DeepSeek-TUI.&lt;/p&gt;
&lt;p&gt;Useful targets reachable as the invoking user:&lt;/p&gt;
&lt;p&gt;- `~/.ssh/authorized_keys`
- `~/.bashrc`, `~/.zshrc`, `~/.profile`
- `~/.gitconfig` (chainable…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7j5w-7r7x-9v27</guid>
    </item>
  </channel>
</rss>
