<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from osv_haskell</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:28:43 +0000</lastBuildDate>
    <item>
      <title>HSEC-2023-0001 — Hash flooding vulnerability in aeson</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0001</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: aeson&lt;/p&gt;
&lt;p&gt;# Hash flooding vulnerability in aeson&lt;/p&gt;
&lt;p&gt;*aeson* was vulnerable to hash flooding (a.k.a. hash DoS).  The
issue is a consequence of the HashMap implementation from
*unordered-containers*.  It results in a denial of service through
CPU consumption.  This technique has been used in real-world attacks
against a variety of languages, libraries and frameworks over the
years.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: aeson&lt;/p&gt;
&lt;p&gt;# Hash flooding vulnerability in aeson&lt;/p&gt;
&lt;p&gt;*aeson* was vulnerable to hash flooding (a.k.a. hash DoS).  The
issue is a consequence of the HashMap implementation from
*unordered-containers*.  It results in a denial of service through
CPU consumption.  This technique has been used in real-world attacks
against a variety of languages, libraries and frameworks over the
years.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0001</guid>
      <pubDate>Fri, 14 Nov 2025 14:45:34 +0000</pubDate>
    </item>
    <item>
      <title>HSEC-2023-0002 — Improper Verification of Cryptographic Signature</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0002</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: biscuit-haskell&lt;/p&gt;
&lt;p&gt;# Improper Verification of Cryptographic Signature&lt;/p&gt;
&lt;p&gt;The Biscuit specification version 1 contains a vulnerable algorithm that allows
malicious actors to forge valid Γ-signatures. Such an attack would allow an
attacker to create a token with any access level. The version 2 of the
specification mandates a different algorithm than gamma signatures and as such
is not affected by this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: biscuit-haskell&lt;/p&gt;
&lt;p&gt;# Improper Verification of Cryptographic Signature&lt;/p&gt;
&lt;p&gt;The Biscuit specification version 1 contains a vulnerable algorithm that allows
malicious actors to forge valid Γ-signatures. Such an attack would allow an
attacker to create a token with any access level. The version 2 of the
specification mandates a different algorithm than gamma signatures and as such
is not affected by this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0002</guid>
      <pubDate>Fri, 14 Nov 2025 14:45:34 +0000</pubDate>
    </item>
    <item>
      <title>HSEC-2023-0003 — code injection in xmonad-contrib</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0003</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: xmonad-contrib&lt;/p&gt;
&lt;p&gt;# code injection in *xmonad-contrib*&lt;/p&gt;
&lt;p&gt;The `XMonad.Hooks.DynamicLog` module in _xmonad-contrib_ before
**0.11.2** allows remote attackers to execute arbitrary commands via a
web page title, which activates the commands when the user clicks on
the xmobar window title, as demonstrated using an action tag.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: xmonad-contrib&lt;/p&gt;
&lt;p&gt;# code injection in *xmonad-contrib*&lt;/p&gt;
&lt;p&gt;The `XMonad.Hooks.DynamicLog` module in _xmonad-contrib_ before
**0.11.2** allows remote attackers to execute arbitrary commands via a
web page title, which activates the commands when the user clicks on
the xmobar window title, as demonstrated using an action tag.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0003</guid>
      <pubDate>Fri, 14 Nov 2025 14:45:34 +0000</pubDate>
    </item>
    <item>
      <title>HSEC-2023-0004 — xml-conduit unbounded entity expansion</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0004</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: xml-conduit&lt;/p&gt;
&lt;p&gt;# xml-conduit unbounded entity expansion&lt;/p&gt;
&lt;p&gt;A vulnerability was found in *xml-conduit*. It has been classified
as problematic.  Affected is an unknown function of the file
`xml-conduit/src/Text/XML/Stream/Parse.hs` of the component DOCTYPE
Entity Expansion Handler. The manipulation leads to infinite loop.
It is possible to launch the attack remotely. Upgrading to version
1.9.1.0 is able to address this issue. The name of the patch is
`4be1021791dcdee8b164d239433a2043dc0939ea`. It is recommended to
upgrade the affected component.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: xml-conduit&lt;/p&gt;
&lt;p&gt;# xml-conduit unbounded entity expansion&lt;/p&gt;
&lt;p&gt;A vulnerability was found in *xml-conduit*. It has been classified
as problematic.  Affected is an unknown function of the file
`xml-conduit/src/Text/XML/Stream/Parse.hs` of the component DOCTYPE
Entity Expansion Handler. The manipulation leads to infinite loop.
It is possible to launch the attack remotely. Upgrading to version
1.9.1.0 is able to address this issue. The name of the patch is
`4be1021791dcdee8b164d239433a2043dc0939ea`. It is recommended to
upgrade the affected component.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0004</guid>
      <pubDate>Fri, 14 Nov 2025 14:45:34 +0000</pubDate>
    </item>
    <item>
      <title>HSEC-2023-0005 — tls-extra: certificate validation does not check Basic Constraints</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0005</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: tls-extra&lt;/p&gt;
&lt;p&gt;# tls-extra: certificate validation does not check Basic Constraints&lt;/p&gt;
&lt;p&gt;*tls-extra* does not check the Basic Constraints extension of a
certificate in certificate chain processing.  Any certificate is
treated as a CA certificate.  As a consequence, anyone who has a
valid certificate can use it to sign another one (with an arbitrary
subject DN/domain name embedded into it) and have it accepted by
*tls*.  This allows MITM attacks on TLS connections.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: tls-extra&lt;/p&gt;
&lt;p&gt;# tls-extra: certificate validation does not check Basic Constraints&lt;/p&gt;
&lt;p&gt;*tls-extra* does not check the Basic Constraints extension of a
certificate in certificate chain processing.  Any certificate is
treated as a CA certificate.  As a consequence, anyone who has a
valid certificate can use it to sign another one (with an arbitrary
subject DN/domain name embedded into it) and have it accepted by
*tls*.  This allows MITM attacks on TLS connections.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0005</guid>
      <pubDate>Fri, 14 Nov 2025 14:45:34 +0000</pubDate>
    </item>
    <item>
      <title>HSEC-2023-0006 — x509-validation does not enforce pathLenConstraint</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0006</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: x509-validation&lt;/p&gt;
&lt;p&gt;# x509-validation does not enforce pathLenConstraint&lt;/p&gt;
&lt;p&gt;*x509-validation* prior to version 1.4.8 did not enforce the
pathLenConstraint value.  Constrained CAs could accidentally (or
deliberately) issue CAs below the maximum depth and
*x509-validation* would accept certificates issued by the
unauthorised intermediate CAs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: x509-validation&lt;/p&gt;
&lt;p&gt;# x509-validation does not enforce pathLenConstraint&lt;/p&gt;
&lt;p&gt;*x509-validation* prior to version 1.4.8 did not enforce the
pathLenConstraint value.  Constrained CAs could accidentally (or
deliberately) issue CAs below the maximum depth and
*x509-validation* would accept certificates issued by the
unauthorised intermediate CAs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0006</guid>
      <pubDate>Fri, 14 Nov 2025 14:45:34 +0000</pubDate>
    </item>
    <item>
      <title>HSEC-2023-0007 — readFloat: memory exhaustion with large exponent</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: base, Hackage: toml-reader&lt;/p&gt;
&lt;p&gt;# `readFloat`: memory exhaustion with large exponent&lt;/p&gt;
&lt;p&gt;`Numeric.readFloat` takes time and memory linear in the size of the
number _denoted_ by the input string.  In particular, processing a
number expressed in scientific notation with a very large exponent
could cause a denial of service.  The slowdown is observable on a
modern machine running GHC 9.4.4:&lt;/p&gt;
&lt;p&gt;```
ghci&amp;gt; import qualified Numeric
ghci&amp;gt; Numeric.readFloat &amp;#34;1e1000000&amp;#34;    -- near instantaneous
[(Infinity,&amp;#34;&amp;#34;)]
ghci&amp;gt; Numeric.readFloat &amp;#34;1e10000000&amp;#34;   -- perceptible pause
[(Infinity,&amp;#34;&amp;#34;)]
ghci&amp;gt; Numeric.readFloat &amp;#34;1e100000000&amp;#34;  -- ~ 3 seconds
[(Infinity,&amp;#34;&amp;#34;)]
ghci&amp;gt; Numeric.readFloat &amp;#34;1e1000000000&amp;#34; -- ~ 35 seconds
[(Infinity,&amp;#34;&amp;#34;)]
```&lt;/p&gt;
&lt;p&gt;## In *base*&lt;/p&gt;
&lt;p&gt;`Numeric.readFloat` is defined for all `RealFrac a =&amp;gt; a`:&lt;/p&gt;
&lt;p&gt;```haskell
readFloat :: RealFrac a =&amp;gt; ReadS a
```&lt;/p&gt;
&lt;p&gt;The `RealFrac` type class does not express any bounds on the size of
values representable in the types for which instances exist, so
bounds checking is not possible (in this *generic* function).
`readFloat` uses to `Text.Read.Lex.numberToRational` which, among
other things, calculates `10 ^ exponent`, which seems to take linear
time and memory.&lt;/p&gt;
&lt;p&gt;**Mitigation:** use `read`.  The `Read` instances for `Float` and
`Double` perform bounds checks on the exponent, via
`Text.Read.Lex.numberToRangedRational`.&lt;/p&gt;
&lt;p&gt;## In *toml-reader*&lt;/p&gt;
&lt;p&gt;The issue was detected in *toml-reader* version 0.1.0.0, and
mitigated in version 0.2.0.0 by immediately returning `Infinity`
when the exponent is large en…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: base, Hackage: toml-reader&lt;/p&gt;
&lt;p&gt;# `readFloat`: memory exhaustion with large exponent&lt;/p&gt;
&lt;p&gt;`Numeric.readFloat` takes time and memory linear in the size of the
number _denoted_ by the input string.  In particular, processing a
number expressed in scientific notation with a very large exponent
could cause a denial of service.  The slowdown is observable on a
modern machine running GHC 9.4.4:&lt;/p&gt;
&lt;p&gt;```
ghci&amp;gt; import qualified Numeric
ghci&amp;gt; Numeric.readFloat &amp;#34;1e1000000&amp;#34;    -- near instantaneous
[(Infinity,&amp;#34;&amp;#34;)]
ghci&amp;gt; Numeric.readFloat &amp;#34;1e10000000&amp;#34;   -- perceptible pause
[(Infinity,&amp;#34;&amp;#34;)]
ghci&amp;gt; Numeric.readFloat &amp;#34;1e100000000&amp;#34;  -- ~ 3 seconds
[(Infinity,&amp;#34;&amp;#34;)]
ghci&amp;gt; Numeric.readFloat &amp;#34;1e1000000000&amp;#34; -- ~ 35 seconds
[(Infinity,&amp;#34;&amp;#34;)]
```&lt;/p&gt;
&lt;p&gt;## In *base*&lt;/p&gt;
&lt;p&gt;`Numeric.readFloat` is defined for all `RealFrac a =&amp;gt; a`:&lt;/p&gt;
&lt;p&gt;```haskell
readFloat :: RealFrac a =&amp;gt; ReadS a
```&lt;/p&gt;
&lt;p&gt;The `RealFrac` type class does not express any bounds on the size of
values representable in the types for which instances exist, so
bounds checking is not possible (in this *generic* function).
`readFloat` uses to `Text.Read.Lex.numberToRational` which, among
other things, calculates `10 ^ exponent`, which seems to take linear
time and memory.&lt;/p&gt;
&lt;p&gt;**Mitigation:** use `read`.  The `Read` instances for `Float` and
`Double` perform bounds checks on the exponent, via
`Text.Read.Lex.numberToRangedRational`.&lt;/p&gt;
&lt;p&gt;## In *toml-reader*&lt;/p&gt;
&lt;p&gt;The issue was detected in *toml-reader* version 0.1.0.0, and
mitigated in version 0.2.0.0 by immediately returning `Infinity`
when the exponent is large en…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0007</guid>
      <pubDate>Fri, 14 Nov 2025 14:45:34 +0000</pubDate>
    </item>
    <item>
      <title>HSEC-2023-0008 — Stored XSS in hledger-web</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0008</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: hledger-web&lt;/p&gt;
&lt;p&gt;# Stored XSS in *hledger-web*&lt;/p&gt;
&lt;p&gt;An issue was discovered in *hledger-web* &amp;lt; 1.23. A Stored Cross-Site
Scripting (XSS) vulnerability exists in `toBloodhoundJson` that
allows an attacker to execute JavaScript by encoding user-controlled
values in a payload with base64 and parsing them with the `atob`
function.&lt;/p&gt;
&lt;p&gt;*hledger-web* forms sanitise obvious JavaScript, but not obfuscated
JavaScript (see [OWASP Filter Evasion Cheat Sheet][cheatsheet]).
This means *hledger-web* instances, especially anonymously-writable
ones like `demo.hledger.org`, could be loaded with malicious
JavaScript to be executed by subsequent visitors.&lt;/p&gt;
&lt;p&gt;[cheatsheet]: https://owasp.org/www-community/xss-filter-evasion-cheatsheet&lt;/p&gt;
&lt;p&gt;Reported by Gaspard Baye and Hamidullah Muslih.  Fix by Arsen
Arsenović.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: hledger-web&lt;/p&gt;
&lt;p&gt;# Stored XSS in *hledger-web*&lt;/p&gt;
&lt;p&gt;An issue was discovered in *hledger-web* &amp;lt; 1.23. A Stored Cross-Site
Scripting (XSS) vulnerability exists in `toBloodhoundJson` that
allows an attacker to execute JavaScript by encoding user-controlled
values in a payload with base64 and parsing them with the `atob`
function.&lt;/p&gt;
&lt;p&gt;*hledger-web* forms sanitise obvious JavaScript, but not obfuscated
JavaScript (see [OWASP Filter Evasion Cheat Sheet][cheatsheet]).
This means *hledger-web* instances, especially anonymously-writable
ones like `demo.hledger.org`, could be loaded with malicious
JavaScript to be executed by subsequent visitors.&lt;/p&gt;
&lt;p&gt;[cheatsheet]: https://owasp.org/www-community/xss-filter-evasion-cheatsheet&lt;/p&gt;
&lt;p&gt;Reported by Gaspard Baye and Hamidullah Muslih.  Fix by Arsen
Arsenović.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0008</guid>
      <pubDate>Fri, 14 Nov 2025 14:45:34 +0000</pubDate>
    </item>
    <item>
      <title>HSEC-2023-0009 — git-annex command injection via malicious SSH hostname</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* command injection via malicious SSH hostname&lt;/p&gt;
&lt;p&gt;*git-annex* was vulnerable to the same class of security hole as
git&amp;#39;s **CVE-2017-1000117**. In several cases, `git-annex` parses a
repository URL, and uses it to generate a `ssh` command, with the
hostname to ssh to coming from the URL. If the hostname it parses is
something like `-eProxyCommand=evil`, this could result in arbitrary
local code execution.&lt;/p&gt;
&lt;p&gt;Some details of URL parsing may prevent the exploit working in some
cases.&lt;/p&gt;
&lt;p&gt;Exploiting this would involve the attacker tricking the victim into
adding a remote something like `ssh://-eProxyCommand=evil/blah`.&lt;/p&gt;
&lt;p&gt;One possible avenue for an attacker that avoids exposing the URL to
the user is to use `initremote` with an SSH remote, so embedding the
URL in the *git-annex* branch. Then the victim would enable it with
`enableremote`.&lt;/p&gt;
&lt;p&gt;This was fixed in version **6.20170818**. Now there&amp;#39;s a `SshHost`
type that is not allowed to start with a dash, and every invocation
of `git-annex` uses a function that takes a `SshHost`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* command injection via malicious SSH hostname&lt;/p&gt;
&lt;p&gt;*git-annex* was vulnerable to the same class of security hole as
git&amp;#39;s **CVE-2017-1000117**. In several cases, `git-annex` parses a
repository URL, and uses it to generate a `ssh` command, with the
hostname to ssh to coming from the URL. If the hostname it parses is
something like `-eProxyCommand=evil`, this could result in arbitrary
local code execution.&lt;/p&gt;
&lt;p&gt;Some details of URL parsing may prevent the exploit working in some
cases.&lt;/p&gt;
&lt;p&gt;Exploiting this would involve the attacker tricking the victim into
adding a remote something like `ssh://-eProxyCommand=evil/blah`.&lt;/p&gt;
&lt;p&gt;One possible avenue for an attacker that avoids exposing the URL to
the user is to use `initremote` with an SSH remote, so embedding the
URL in the *git-annex* branch. Then the victim would enable it with
`enableremote`.&lt;/p&gt;
&lt;p&gt;This was fixed in version **6.20170818**. Now there&amp;#39;s a `SshHost`
type that is not allowed to start with a dash, and every invocation
of `git-annex` uses a function that takes a `SshHost`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0009</guid>
      <pubDate>Fri, 14 Nov 2025 14:45:34 +0000</pubDate>
    </item>
    <item>
      <title>HSEC-2023-0010 — git-annex private data exfiltration to compromised remote</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0010</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* private data exfiltration to compromised remote&lt;/p&gt;
&lt;p&gt;Some uses of git-annex were vulnerable to a private data exposure
and exfiltration attack. It could expose the content of files
located outside the *git-annex* repository, or content from a
private web server on localhost or the LAN.  Joey Hess discovered
this attack.&lt;/p&gt;
&lt;p&gt;To perform this attack, the attacker needs to have control over one
of the remotes of the victim&amp;#39;s *git-annex* repository. For example,
they may provide a public *git-annex* repository that the victim
clones. Or, equivalantly, the attacker could have read access to the
victim&amp;#39;s *git-annex* repository or a repository it pushes to, and
some channel to get commits into it (e.g. pull requests).&lt;/p&gt;
&lt;p&gt;These exploits are most likely to succeed when the victim is running
the `git-annex` assistant, or is periodically running `git annex
sync --content`.&lt;/p&gt;
&lt;p&gt;To perform the attack the attacker runs `git-annex addurl --relaxed
file:///etc/passwd` and commits this to the repository in some out
of the way place.  After the victim&amp;#39;s git repository receives that
change, `git-annex` follows the attacker-provided URL to the private
data, which it stores in the *git-annex* repository.  From there it
transfers the content to the remote *git-annex* repository that the
attacker has access to.&lt;/p&gt;
&lt;p&gt;As well as `file:///` URLs, the attacker can use URLs to private web
servers.  The URL can also be one that the attacker controls, that
redirects to a URL that is accessible to the victim…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* private data exfiltration to compromised remote&lt;/p&gt;
&lt;p&gt;Some uses of git-annex were vulnerable to a private data exposure
and exfiltration attack. It could expose the content of files
located outside the *git-annex* repository, or content from a
private web server on localhost or the LAN.  Joey Hess discovered
this attack.&lt;/p&gt;
&lt;p&gt;To perform this attack, the attacker needs to have control over one
of the remotes of the victim&amp;#39;s *git-annex* repository. For example,
they may provide a public *git-annex* repository that the victim
clones. Or, equivalantly, the attacker could have read access to the
victim&amp;#39;s *git-annex* repository or a repository it pushes to, and
some channel to get commits into it (e.g. pull requests).&lt;/p&gt;
&lt;p&gt;These exploits are most likely to succeed when the victim is running
the `git-annex` assistant, or is periodically running `git annex
sync --content`.&lt;/p&gt;
&lt;p&gt;To perform the attack the attacker runs `git-annex addurl --relaxed
file:///etc/passwd` and commits this to the repository in some out
of the way place.  After the victim&amp;#39;s git repository receives that
change, `git-annex` follows the attacker-provided URL to the private
data, which it stores in the *git-annex* repository.  From there it
transfers the content to the remote *git-annex* repository that the
attacker has access to.&lt;/p&gt;
&lt;p&gt;As well as `file:///` URLs, the attacker can use URLs to private web
servers.  The URL can also be one that the attacker controls, that
redirects to a URL that is accessible to the victim…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0010</guid>
      <pubDate>Fri, 14 Nov 2025 14:45:34 +0000</pubDate>
    </item>
  </channel>
</rss>
