<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:33:42 +0000</lastBuildDate>
    <item>
      <title>BREW-aider-CVE-2026-78679 — GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (in…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-78679</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file&amp;#39;s contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f&amp;#39;s tag instance).&lt;/p&gt;
&lt;p&gt;## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = [&amp;#34;--file&amp;#34;,&amp;#34;-F&amp;#34;]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=&amp;#34;--file=&amp;lt;path&amp;gt;&amp;#34;` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file&amp;#39;s contents.&lt;/p&gt;
&lt;p&gt;## Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```python
from git import TagReference
t = TagReference.create(repo, &amp;#34;vpwn&amp;#34;, reference=&amp;#34;--file=/home/app/.ssh/id_rsa&amp;#34;)
print(t.tag.message)   # content…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file&amp;#39;s contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f&amp;#39;s tag instance).&lt;/p&gt;
&lt;p&gt;## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = [&amp;#34;--file&amp;#34;,&amp;#34;-F&amp;#34;]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=&amp;#34;--file=&amp;lt;path&amp;gt;&amp;#34;` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file&amp;#39;s contents.&lt;/p&gt;
&lt;p&gt;## Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```python
from git import TagReference
t = TagReference.create(repo, &amp;#34;vpwn&amp;#34;, reference=&amp;#34;--file=/home/app/.ssh/id_rsa&amp;#34;)
print(t.tag.message)   # content…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-78679</guid>
    </item>
    <item>
      <title>CVE-2026-78679 — GitPython before 3.1.59 Arbitrary File Read via TagReference.create</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-78679</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; gitpython-developers GitPython&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=&amp;lt;path&amp;gt; to read arbitrary files, with contents returned in the annotated tag message.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; gitpython-developers GitPython&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=&amp;lt;path&amp;gt; to read arbitrary files, with contents returned in the annotated tag message.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-78679</guid>
    </item>
    <item>
      <title>GHSA-3wxw-xv34-2frg — GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (in…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3wxw-xv34-2frg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: GitPython&lt;/p&gt;
&lt;p&gt;## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file&amp;#39;s contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f&amp;#39;s tag instance).&lt;/p&gt;
&lt;p&gt;## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = [&amp;#34;--file&amp;#34;,&amp;#34;-F&amp;#34;]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=&amp;#34;--file=&amp;lt;path&amp;gt;&amp;#34;` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file&amp;#39;s contents.&lt;/p&gt;
&lt;p&gt;## Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```python
from git import TagReference
t = TagReference.create(repo, &amp;#34;vpwn&amp;#34;, reference=&amp;#34;--file=/home/app/.ssh/id_rsa&amp;#34;)
print(t.tag.message)   # content…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: GitPython&lt;/p&gt;
&lt;p&gt;## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file&amp;#39;s contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f&amp;#39;s tag instance).&lt;/p&gt;
&lt;p&gt;## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = [&amp;#34;--file&amp;#34;,&amp;#34;-F&amp;#34;]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects **kwargs only**. The dangerous values `path` and `reference` are POSITIONALS (`args = (path, reference)`, tag.py:156), placed before any `--`. A user-influenced `reference=&amp;#34;--file=&amp;lt;path&amp;gt;&amp;#34;` therefore reaches `git tag` as the exact `--file` option the fix intended to block, creating an annotated tag whose message is the file&amp;#39;s contents.&lt;/p&gt;
&lt;p&gt;## Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via `tagref.tag.message`. Requires the embedding application to forward a caller-influenced `reference` value into `TagReference.create()` (pure VALUE control — the CVE-2026-42215 threat model). Default `allow_unsafe_options=False`.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```python
from git import TagReference
t = TagReference.create(repo, &amp;#34;vpwn&amp;#34;, reference=&amp;#34;--file=/home/app/.ssh/id_rsa&amp;#34;)
print(t.tag.message)   # content…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3wxw-xv34-2frg</guid>
    </item>
  </channel>
</rss>
