diff --git a/advisories/BREW-acronym-CVE-2026-62384.json b/advisories/BREW-acronym-CVE-2026-62384.json new file mode 100644 index 0000000000..c5214d94d8 --- /dev/null +++ b/advisories/BREW-acronym-CVE-2026-62384.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-acronym-CVE-2026-62384", + "published": "2026-09-04T08:43:15Z", + "modified": "2026-09-04T08:43:15Z", + "upstream": [ + "PYSEC-2026-3789", + "CVE-2026-62384", + "GHSA-f833-7jw8-xwrv" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "acronym", + "purl": "pkg:brew/acronym" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.0.0_5" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.10.2", + "resource": "nltk", + "resource_purl": "pkg:pypi/nltk@3.10.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + } + ] + }, + "details": "NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/nltk-framenetcorpusreader-symlink-sandbox-bypass-before" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv" + } + ] +} diff --git a/advisories/BREW-acronym-CVE-2026-71514.json b/advisories/BREW-acronym-CVE-2026-71514.json index a2361becfa..dd69c3fc4b 100644 --- a/advisories/BREW-acronym-CVE-2026-71514.json +++ b/advisories/BREW-acronym-CVE-2026-71514.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-acronym-CVE-2026-71514", "published": "2026-09-03T08:45:00Z", - "modified": "2026-09-03T08:45:00Z", + "modified": "2026-09-04T08:42:59Z", "upstream": [ "GHSA-cv22-g7mw-8v73", - "CVE-2026-71514" + "CVE-2026-71514", + "PYSEC-2026-3790" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aider-CVE-2026-76221.json b/advisories/BREW-aider-CVE-2026-76221.json index c51dddddde..30ab7346dc 100644 --- a/advisories/BREW-aider-CVE-2026-76221.json +++ b/advisories/BREW-aider-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-aider-CVE-2026-76221", "published": "2026-08-20T08:39:09Z", - "modified": "2026-08-20T08:39:09Z", + "modified": "2026-09-04T08:43:32Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aider-CVE-2026-76222.json b/advisories/BREW-aider-CVE-2026-76222.json index e38331819e..4e9e92620b 100644 --- a/advisories/BREW-aider-CVE-2026-76222.json +++ b/advisories/BREW-aider-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-aider-CVE-2026-76222", "published": "2026-08-20T08:39:09Z", - "modified": "2026-08-20T08:39:09Z", + "modified": "2026-09-04T08:43:32Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aider-CVE-2026-78675.json b/advisories/BREW-aider-CVE-2026-78675.json new file mode 100644 index 0000000000..698cedfef4 --- /dev/null +++ b/advisories/BREW-aider-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-aider-CVE-2026-78675", + "published": "2026-09-04T08:43:32Z", + "modified": "2026-09-04T08:43:32Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "aider", + "purl": "pkg:brew/aider" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.46" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-aider-CVE-2026-78676.json b/advisories/BREW-aider-CVE-2026-78676.json new file mode 100644 index 0000000000..20930f558b --- /dev/null +++ b/advisories/BREW-aider-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-aider-CVE-2026-78676", + "published": "2026-09-04T08:43:32Z", + "modified": "2026-09-04T08:43:32Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "aider", + "purl": "pkg:brew/aider" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.46" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-aider-CVE-2026-78677.json b/advisories/BREW-aider-CVE-2026-78677.json new file mode 100644 index 0000000000..e447ef9abe --- /dev/null +++ b/advisories/BREW-aider-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-aider-CVE-2026-78677", + "published": "2026-09-04T08:43:32Z", + "modified": "2026-09-04T08:43:32Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "aider", + "purl": "pkg:brew/aider" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.46" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-aider-CVE-2026-78678.json b/advisories/BREW-aider-CVE-2026-78678.json new file mode 100644 index 0000000000..8d12ebe21e --- /dev/null +++ b/advisories/BREW-aider-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-aider-CVE-2026-78678", + "published": "2026-09-04T08:43:32Z", + "modified": "2026-09-04T08:43:32Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "aider", + "purl": "pkg:brew/aider" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.46" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-aider-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-aider-GHSA-hmq2-w58f-27jc.json index b1206459b7..5be494f886 100644 --- a/advisories/BREW-aider-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-aider-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-aider-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:35:12Z", - "modified": "2026-08-29T08:37:49Z", + "modified": "2026-09-04T08:43:32Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aider-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-aider-GHSA-jm78-9fvv-mhgr.json index df2d0256e7..9364bb99b2 100644 --- a/advisories/BREW-aider-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-aider-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-aider-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:35:12Z", - "modified": "2026-08-29T08:37:49Z", + "modified": "2026-09-04T08:43:32Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-allure-CVE-2026-55846.json b/advisories/BREW-allure-CVE-2026-55846.json index 84ffbefda0..7aff386d3e 100644 --- a/advisories/BREW-allure-CVE-2026-55846.json +++ b/advisories/BREW-allure-CVE-2026-55846.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-allure-CVE-2026-55846", "published": "2026-08-13T16:35:13Z", - "modified": "2026-08-28T12:17:10Z", + "modified": "2026-09-04T08:43:33Z", "upstream": [ "GHSA-82cg-3hv7-74gc", "CVE-2026-55846" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "Maven", "name": "io.qameta.allure:allure-commandline", - "subject_version": "2.46.0", - "key": "pkg:maven/io.qameta.allure/allure-commandline@2.46.0" + "subject_version": "2.46.1", + "key": "pkg:maven/io.qameta.allure/allure-commandline@2.46.1" } ] }, diff --git a/advisories/BREW-apm-CVE-2026-76221.json b/advisories/BREW-apm-CVE-2026-76221.json index 88f4818c51..84d394c18a 100644 --- a/advisories/BREW-apm-CVE-2026-76221.json +++ b/advisories/BREW-apm-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-76221", "published": "2026-08-20T08:39:48Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-04T08:44:14Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-76222.json b/advisories/BREW-apm-CVE-2026-76222.json index a9509dfae9..3bbb755655 100644 --- a/advisories/BREW-apm-CVE-2026-76222.json +++ b/advisories/BREW-apm-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-76222", "published": "2026-08-20T08:39:48Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-04T08:44:14Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-78675.json b/advisories/BREW-apm-CVE-2026-78675.json new file mode 100644 index 0000000000..51bd38b8ab --- /dev/null +++ b/advisories/BREW-apm-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-apm-CVE-2026-78675", + "published": "2026-09-04T08:44:32Z", + "modified": "2026-09-04T08:44:32Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "apm", + "purl": "pkg:brew/apm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.29.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-apm-CVE-2026-78676.json b/advisories/BREW-apm-CVE-2026-78676.json new file mode 100644 index 0000000000..4221ddd6ef --- /dev/null +++ b/advisories/BREW-apm-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-apm-CVE-2026-78676", + "published": "2026-09-04T08:44:32Z", + "modified": "2026-09-04T08:44:32Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "apm", + "purl": "pkg:brew/apm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.29.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-apm-CVE-2026-78677.json b/advisories/BREW-apm-CVE-2026-78677.json new file mode 100644 index 0000000000..a5e72b1e38 --- /dev/null +++ b/advisories/BREW-apm-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-apm-CVE-2026-78677", + "published": "2026-09-04T08:44:32Z", + "modified": "2026-09-04T08:44:32Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "apm", + "purl": "pkg:brew/apm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.29.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-apm-CVE-2026-78678.json b/advisories/BREW-apm-CVE-2026-78678.json new file mode 100644 index 0000000000..38a0ee3238 --- /dev/null +++ b/advisories/BREW-apm-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-apm-CVE-2026-78678", + "published": "2026-09-04T08:44:32Z", + "modified": "2026-09-04T08:44:32Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "apm", + "purl": "pkg:brew/apm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.29.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-apm-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-apm-GHSA-hmq2-w58f-27jc.json index 1b14aee597..570782f031 100644 --- a/advisories/BREW-apm-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-apm-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-04T08:44:14Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-apm-GHSA-jm78-9fvv-mhgr.json index a3c6f1e965..b50182f82f 100644 --- a/advisories/BREW-apm-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-apm-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-04T08:44:14Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-btcli-CVE-2026-76221.json b/advisories/BREW-btcli-CVE-2026-76221.json index 23374ec8e7..bb398f8153 100644 --- a/advisories/BREW-btcli-CVE-2026-76221.json +++ b/advisories/BREW-btcli-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-btcli-CVE-2026-76221", "published": "2026-08-20T08:42:00Z", - "modified": "2026-08-20T08:42:00Z", + "modified": "2026-09-04T08:47:49Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-btcli-CVE-2026-76222.json b/advisories/BREW-btcli-CVE-2026-76222.json index 6be2482023..f8af73204e 100644 --- a/advisories/BREW-btcli-CVE-2026-76222.json +++ b/advisories/BREW-btcli-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-btcli-CVE-2026-76222", "published": "2026-08-20T08:42:00Z", - "modified": "2026-08-20T08:42:00Z", + "modified": "2026-09-04T08:47:49Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-btcli-CVE-2026-78675.json b/advisories/BREW-btcli-CVE-2026-78675.json new file mode 100644 index 0000000000..58e0a99aac --- /dev/null +++ b/advisories/BREW-btcli-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-btcli-CVE-2026-78675", + "published": "2026-09-04T08:47:49Z", + "modified": "2026-09-04T08:47:49Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "btcli", + "purl": "pkg:brew/btcli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.51" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-btcli-CVE-2026-78676.json b/advisories/BREW-btcli-CVE-2026-78676.json new file mode 100644 index 0000000000..2d3f9c166a --- /dev/null +++ b/advisories/BREW-btcli-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-btcli-CVE-2026-78676", + "published": "2026-09-04T08:47:49Z", + "modified": "2026-09-04T08:47:49Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "btcli", + "purl": "pkg:brew/btcli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.51" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-btcli-CVE-2026-78677.json b/advisories/BREW-btcli-CVE-2026-78677.json new file mode 100644 index 0000000000..c93f455d53 --- /dev/null +++ b/advisories/BREW-btcli-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-btcli-CVE-2026-78677", + "published": "2026-09-04T08:47:49Z", + "modified": "2026-09-04T08:47:49Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "btcli", + "purl": "pkg:brew/btcli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.51" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-btcli-CVE-2026-78678.json b/advisories/BREW-btcli-CVE-2026-78678.json new file mode 100644 index 0000000000..13ed904e90 --- /dev/null +++ b/advisories/BREW-btcli-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-btcli-CVE-2026-78678", + "published": "2026-09-04T08:47:49Z", + "modified": "2026-09-04T08:47:49Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "btcli", + "purl": "pkg:brew/btcli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.51" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-btcli-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-btcli-GHSA-hmq2-w58f-27jc.json index ffd362dcfd..6cc1fde437 100644 --- a/advisories/BREW-btcli-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-btcli-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-btcli-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-29T08:41:30Z", + "modified": "2026-09-04T08:47:49Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-btcli-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-btcli-GHSA-jm78-9fvv-mhgr.json index 8dbad76d32..16de6c8124 100644 --- a/advisories/BREW-btcli-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-btcli-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-btcli-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-29T08:41:30Z", + "modified": "2026-09-04T08:47:49Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cf2tf-CVE-2026-76221.json b/advisories/BREW-cf2tf-CVE-2026-76221.json index e2f7c7041e..0be2b289c6 100644 --- a/advisories/BREW-cf2tf-CVE-2026-76221.json +++ b/advisories/BREW-cf2tf-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cf2tf-CVE-2026-76221", "published": "2026-08-20T08:42:33Z", - "modified": "2026-08-20T08:42:33Z", + "modified": "2026-09-04T08:48:55Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cf2tf-CVE-2026-76222.json b/advisories/BREW-cf2tf-CVE-2026-76222.json index f8f23bf85c..0eb90994c4 100644 --- a/advisories/BREW-cf2tf-CVE-2026-76222.json +++ b/advisories/BREW-cf2tf-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cf2tf-CVE-2026-76222", "published": "2026-08-20T08:42:33Z", - "modified": "2026-08-20T08:42:33Z", + "modified": "2026-09-04T08:48:55Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cf2tf-CVE-2026-78675.json b/advisories/BREW-cf2tf-CVE-2026-78675.json new file mode 100644 index 0000000000..c411f1b907 --- /dev/null +++ b/advisories/BREW-cf2tf-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cf2tf-CVE-2026-78675", + "published": "2026-09-04T08:48:55Z", + "modified": "2026-09-04T08:48:55Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cf2tf", + "purl": "pkg:brew/cf2tf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-cf2tf-CVE-2026-78676.json b/advisories/BREW-cf2tf-CVE-2026-78676.json new file mode 100644 index 0000000000..1085ce0ef2 --- /dev/null +++ b/advisories/BREW-cf2tf-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cf2tf-CVE-2026-78676", + "published": "2026-09-04T08:48:55Z", + "modified": "2026-09-04T08:48:55Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cf2tf", + "purl": "pkg:brew/cf2tf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-cf2tf-CVE-2026-78677.json b/advisories/BREW-cf2tf-CVE-2026-78677.json new file mode 100644 index 0000000000..af5ff5eff0 --- /dev/null +++ b/advisories/BREW-cf2tf-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cf2tf-CVE-2026-78677", + "published": "2026-09-04T08:48:55Z", + "modified": "2026-09-04T08:48:55Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cf2tf", + "purl": "pkg:brew/cf2tf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-cf2tf-CVE-2026-78678.json b/advisories/BREW-cf2tf-CVE-2026-78678.json new file mode 100644 index 0000000000..5bd65b1016 --- /dev/null +++ b/advisories/BREW-cf2tf-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cf2tf-CVE-2026-78678", + "published": "2026-09-04T08:48:55Z", + "modified": "2026-09-04T08:48:55Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cf2tf", + "purl": "pkg:brew/cf2tf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-cf2tf-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-cf2tf-GHSA-hmq2-w58f-27jc.json index 3ea1c2c266..546b6644e3 100644 --- a/advisories/BREW-cf2tf-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-cf2tf-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cf2tf-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-29T08:42:08Z", + "modified": "2026-09-04T08:48:55Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cf2tf-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-cf2tf-GHSA-jm78-9fvv-mhgr.json index f75e3acc9b..347956bd77 100644 --- a/advisories/BREW-cf2tf-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-cf2tf-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cf2tf-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-29T08:42:08Z", + "modified": "2026-09-04T08:48:55Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-checkov-CVE-2026-76221.json b/advisories/BREW-checkov-CVE-2026-76221.json index 3c9e708465..3900c9ed19 100644 --- a/advisories/BREW-checkov-CVE-2026-76221.json +++ b/advisories/BREW-checkov-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-checkov-CVE-2026-76221", "published": "2026-08-20T08:43:02Z", - "modified": "2026-08-20T08:43:02Z", + "modified": "2026-09-04T08:50:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-checkov-CVE-2026-76222.json b/advisories/BREW-checkov-CVE-2026-76222.json index 4ff41f619b..8b82fb5676 100644 --- a/advisories/BREW-checkov-CVE-2026-76222.json +++ b/advisories/BREW-checkov-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-checkov-CVE-2026-76222", "published": "2026-08-20T08:43:02Z", - "modified": "2026-08-20T08:43:02Z", + "modified": "2026-09-04T08:50:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-checkov-CVE-2026-78675.json b/advisories/BREW-checkov-CVE-2026-78675.json new file mode 100644 index 0000000000..ebdf290424 --- /dev/null +++ b/advisories/BREW-checkov-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-checkov-CVE-2026-78675", + "published": "2026-09-04T08:50:22Z", + "modified": "2026-09-04T08:50:22Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "checkov", + "purl": "pkg:brew/checkov" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.3.10" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-checkov-CVE-2026-78676.json b/advisories/BREW-checkov-CVE-2026-78676.json new file mode 100644 index 0000000000..80236f837d --- /dev/null +++ b/advisories/BREW-checkov-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-checkov-CVE-2026-78676", + "published": "2026-09-04T08:50:22Z", + "modified": "2026-09-04T08:50:22Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "checkov", + "purl": "pkg:brew/checkov" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.3.10" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-checkov-CVE-2026-78677.json b/advisories/BREW-checkov-CVE-2026-78677.json new file mode 100644 index 0000000000..189f8e63d3 --- /dev/null +++ b/advisories/BREW-checkov-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-checkov-CVE-2026-78677", + "published": "2026-09-04T08:50:22Z", + "modified": "2026-09-04T08:50:22Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "checkov", + "purl": "pkg:brew/checkov" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.3.10" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-checkov-CVE-2026-78678.json b/advisories/BREW-checkov-CVE-2026-78678.json new file mode 100644 index 0000000000..cc6a5b1ffd --- /dev/null +++ b/advisories/BREW-checkov-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-checkov-CVE-2026-78678", + "published": "2026-09-04T08:50:22Z", + "modified": "2026-09-04T08:50:22Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "checkov", + "purl": "pkg:brew/checkov" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.3.10" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-checkov-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-checkov-GHSA-hmq2-w58f-27jc.json index a5a9815a9d..0bdc3a8403 100644 --- a/advisories/BREW-checkov-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-checkov-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-checkov-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:39:32Z", - "modified": "2026-08-29T08:42:40Z", + "modified": "2026-09-04T08:50:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-checkov-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-checkov-GHSA-jm78-9fvv-mhgr.json index f3d21283d5..b254944beb 100644 --- a/advisories/BREW-checkov-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-checkov-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-checkov-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:39:32Z", - "modified": "2026-08-29T08:42:40Z", + "modified": "2026-09-04T08:50:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-claude-code-templates-CVE-2026-73222.json b/advisories/BREW-claude-code-templates-CVE-2026-73222.json new file mode 100644 index 0000000000..a736d9bf77 --- /dev/null +++ b/advisories/BREW-claude-code-templates-CVE-2026-73222.json @@ -0,0 +1,81 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-claude-code-templates-CVE-2026-73222", + "published": "2026-09-04T08:51:25Z", + "modified": "2026-09-04T08:51:25Z", + "upstream": [ + "GHSA-79wm-x847-7cvg", + "CVE-2026-73222" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "claude-code-templates", + "purl": "pkg:brew/claude-code-templates" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.29.4" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.29.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "npm", + "name": "claude-code-templates", + "subject_version": "1.29.4", + "key": "pkg:npm/claude-code-templates@1.29.4" + } + ] + }, + "summary": "Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)", + "details": "### Summary\n`npx claude-code-templates --studio` launches \"Claude Code Studio\", an Express HTTP server (`cli-tool/src/sandbox-server.js`, default port 3444) that binds to **all interfaces** (`0.0.0.0`), sets `Access-Control-Allow-Origin: *`, and requires **no authentication**. Two POST endpoints pass attacker-controlled request-body fields into `child_process.spawn(..., { shell: true })`. Because `shell: true` makes Node join the argv array into a single `sh -c` string, the fields are parsed by the shell and metacharacters execute. Any unauthenticated attacker who can reach the port — a malicious web page the developer visits, or anyone on the same LAN — can execute arbitrary OS commands on the developer's machine.\n\n### Details\nIn `cli-tool/src/sandbox-server.js`:\n\n- `app.listen(PORT, ...)` is called with no host argument, so the server listens on `0.0.0.0` / `::` (reachable from the LAN, not just localhost).\n- The CORS middleware sends `Access-Control-Allow-Origin: *` and answers the preflight `OPTIONS` for any origin, so a browser will deliver cross-origin POSTs to it.\n- There is no authentication on any endpoint.\n\nThe vulnerable sinks:\n\n1. `POST /api/execute` — the `prompt` body field flows into `executeLocalTask()`:\n ```js\n const child = spawn('claude', [finalPrompt], { /* ... */ shell: true });\n The only validation on prompt is a length check (>= 10 chars). With shell: true, finalPrompt is interpreted by the shell.\n\n2. POST /api/install-agent — the agentName body field:\nconst child = spawn('npx', ['claude-code-templates@latest', '--agent', agentName, '--yes'], { /* ... */ shell: true });\n2. agentName is used unvalidated. (The same unsafe pattern is also reachable through /api/execute's agent field via checkAndInstallAgent().)\n\nRoot cause: spawn(cmd, argsArray, { shell: true }) does not keep argsArray as separate argv entries — Node builds cmd + ' ' + argsArray.join(' ') and runs it via sh -c, so every element is subject to shell parsing.\n\nPoC\n\n# Victim\nnpx claude-code-templates --studio # server on 0.0.0.0:3444\n\n# Attacker (another LAN host, or a malicious web page fetch(), or locally)\ncurl -s -X POST http://127.0.0.1:3444/api/execute \\\n -H 'Content-Type: application/json' \\\n --data '{\"prompt\":\"aaaaaaaaaa; touch /tmp/CCT_RCE_PROOF\",\"mode\":\"local\"}'\n\ncurl -s -X POST http://127.0.0.1:3444/api/install-agent \\\n -H 'Content-Type: application/json' \\\n --data '{\"agentName\":\"x; touch /tmp/CCT_AGENT_PROOF #\"}'\n\nls -la /tmp/CCT_RCE_PROOF /tmp/CCT_AGENT_PROOF # both created => injected commands ran\nThe aaaaaaaaaa padding satisfies the 10-char minimum, then ; (or $(...), or backticks) starts the injected command. claude/npx do not even need to be installed — the injected segment runs regardless.\n\nConfirmed at runtime on v1.28.13 (Node 22, Linux): both marker files were created, the server listened on *:3444, and an OPTIONS preflight from Origin: https://evil.example returned 200 with Access-Control-Allow-Origin: *.\n\nImpact\n\nUnauthenticated remote code execution (CWE-78) on any machine running --studio. Two reachability paths:\n- Drive-by: a developer running --studio who visits an attacker-controlled web page — the page's cross-origin fetch() (Content-Type application/json) passes the wildcard CORS preflight and delivers the POST, achieving RCE with no other interaction.\n- LAN: because the server binds 0.0.0.0, anyone on the same network (office, co-working space, public Wi-Fi) can hit port 3444 directly.\n\nImpact is full compromise of the developer's user account (arbitrary command execution with the developer's privileges): source code, SSH keys, cloud credentials, and .env secrets.\n\nSuggested fix\n\n- Remove shell: true from all three spawns so arguments stay discrete argv entries (kills the injection).\n- Validate agentName against a strict allowlist (^[A-Za-z0-9._/-]+$).\n- Bind to loopback only (app.listen(PORT, '127.0.0.1', ...)).\n- Replace the wildcard CORS with a same-origin allowlist and reject other origins.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/davila7/claude-code-templates/security/advisories/GHSA-79wm-x847-7cvg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73222" + }, + { + "type": "WEB", + "url": "https://github.com/davila7/claude-code-templates/commit/bc4618b07232633c1c0aac12a43e436268d31783" + }, + { + "type": "PACKAGE", + "url": "https://github.com/davila7/claude-code-templates" + }, + { + "type": "WEB", + "url": "https://github.com/davila7/claude-code-templates/blob/main/CHANGELOG.md" + } + ] +} diff --git a/advisories/BREW-cobo-cli-CVE-2026-76221.json b/advisories/BREW-cobo-cli-CVE-2026-76221.json index 5ad3575d1b..d36a26716b 100644 --- a/advisories/BREW-cobo-cli-CVE-2026-76221.json +++ b/advisories/BREW-cobo-cli-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cobo-cli-CVE-2026-76221", "published": "2026-08-20T08:43:30Z", - "modified": "2026-08-29T08:43:55Z", + "modified": "2026-09-04T08:51:28Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -44,6 +45,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cobo-cli-CVE-2026-76222.json b/advisories/BREW-cobo-cli-CVE-2026-76222.json index 15ff6c519e..6c90373abe 100644 --- a/advisories/BREW-cobo-cli-CVE-2026-76222.json +++ b/advisories/BREW-cobo-cli-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cobo-cli-CVE-2026-76222", "published": "2026-08-20T08:43:30Z", - "modified": "2026-08-29T08:43:55Z", + "modified": "2026-09-04T08:51:28Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -44,6 +45,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cobo-cli-CVE-2026-78675.json b/advisories/BREW-cobo-cli-CVE-2026-78675.json new file mode 100644 index 0000000000..dcfc5749a2 --- /dev/null +++ b/advisories/BREW-cobo-cli-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cobo-cli-CVE-2026-78675", + "published": "2026-09-04T08:51:28Z", + "modified": "2026-09-04T08:51:28Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cobo-cli", + "purl": "pkg:brew/cobo-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.50" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-cobo-cli-CVE-2026-78676.json b/advisories/BREW-cobo-cli-CVE-2026-78676.json new file mode 100644 index 0000000000..f92e53f45e --- /dev/null +++ b/advisories/BREW-cobo-cli-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cobo-cli-CVE-2026-78676", + "published": "2026-09-04T08:51:28Z", + "modified": "2026-09-04T08:51:28Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cobo-cli", + "purl": "pkg:brew/cobo-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.50" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-cobo-cli-CVE-2026-78677.json b/advisories/BREW-cobo-cli-CVE-2026-78677.json new file mode 100644 index 0000000000..ad746195ea --- /dev/null +++ b/advisories/BREW-cobo-cli-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cobo-cli-CVE-2026-78677", + "published": "2026-09-04T08:51:28Z", + "modified": "2026-09-04T08:51:28Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cobo-cli", + "purl": "pkg:brew/cobo-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.50" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-cobo-cli-CVE-2026-78678.json b/advisories/BREW-cobo-cli-CVE-2026-78678.json new file mode 100644 index 0000000000..cfa9e42ea9 --- /dev/null +++ b/advisories/BREW-cobo-cli-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cobo-cli-CVE-2026-78678", + "published": "2026-09-04T08:51:28Z", + "modified": "2026-09-04T08:51:28Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cobo-cli", + "purl": "pkg:brew/cobo-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.50" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-cobo-cli-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-cobo-cli-GHSA-hmq2-w58f-27jc.json index 1222602b3b..7a7bfb4db0 100644 --- a/advisories/BREW-cobo-cli-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-cobo-cli-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cobo-cli-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:40:10Z", - "modified": "2026-08-29T08:43:55Z", + "modified": "2026-09-04T08:51:28Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -44,6 +45,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cobo-cli-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-cobo-cli-GHSA-jm78-9fvv-mhgr.json index ef83a78368..5be80e53fd 100644 --- a/advisories/BREW-cobo-cli-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-cobo-cli-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cobo-cli-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:40:10Z", - "modified": "2026-08-29T08:43:55Z", + "modified": "2026-09-04T08:51:28Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -44,6 +45,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-conda-lock-CVE-2026-76221.json b/advisories/BREW-conda-lock-CVE-2026-76221.json index 88784d39d4..67f8b125e5 100644 --- a/advisories/BREW-conda-lock-CVE-2026-76221.json +++ b/advisories/BREW-conda-lock-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-conda-lock-CVE-2026-76221", "published": "2026-08-20T08:44:16Z", - "modified": "2026-08-20T08:44:16Z", + "modified": "2026-09-04T08:51:51Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-conda-lock-CVE-2026-76222.json b/advisories/BREW-conda-lock-CVE-2026-76222.json index ab0e9f07aa..4c29d8410b 100644 --- a/advisories/BREW-conda-lock-CVE-2026-76222.json +++ b/advisories/BREW-conda-lock-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-conda-lock-CVE-2026-76222", "published": "2026-08-20T08:44:16Z", - "modified": "2026-08-20T08:44:16Z", + "modified": "2026-09-04T08:51:51Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-conda-lock-CVE-2026-78675.json b/advisories/BREW-conda-lock-CVE-2026-78675.json new file mode 100644 index 0000000000..3bc5bf79f5 --- /dev/null +++ b/advisories/BREW-conda-lock-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-conda-lock-CVE-2026-78675", + "published": "2026-09-04T08:51:51Z", + "modified": "2026-09-04T08:51:51Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "conda-lock", + "purl": "pkg:brew/conda-lock" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-conda-lock-CVE-2026-78676.json b/advisories/BREW-conda-lock-CVE-2026-78676.json new file mode 100644 index 0000000000..b72df10415 --- /dev/null +++ b/advisories/BREW-conda-lock-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-conda-lock-CVE-2026-78676", + "published": "2026-09-04T08:51:51Z", + "modified": "2026-09-04T08:51:51Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "conda-lock", + "purl": "pkg:brew/conda-lock" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-conda-lock-CVE-2026-78677.json b/advisories/BREW-conda-lock-CVE-2026-78677.json new file mode 100644 index 0000000000..051be4ee30 --- /dev/null +++ b/advisories/BREW-conda-lock-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-conda-lock-CVE-2026-78677", + "published": "2026-09-04T08:51:51Z", + "modified": "2026-09-04T08:51:51Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "conda-lock", + "purl": "pkg:brew/conda-lock" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-conda-lock-CVE-2026-78678.json b/advisories/BREW-conda-lock-CVE-2026-78678.json new file mode 100644 index 0000000000..4de7233ecf --- /dev/null +++ b/advisories/BREW-conda-lock-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-conda-lock-CVE-2026-78678", + "published": "2026-09-04T08:51:51Z", + "modified": "2026-09-04T08:51:51Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "conda-lock", + "purl": "pkg:brew/conda-lock" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-conda-lock-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-conda-lock-GHSA-hmq2-w58f-27jc.json index 795b61b515..024e1f99f2 100644 --- a/advisories/BREW-conda-lock-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-conda-lock-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-conda-lock-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:41:05Z", - "modified": "2026-08-29T08:44:26Z", + "modified": "2026-09-04T08:51:51Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-conda-lock-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-conda-lock-GHSA-jm78-9fvv-mhgr.json index c927860288..1c60a32ecb 100644 --- a/advisories/BREW-conda-lock-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-conda-lock-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-conda-lock-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:41:05Z", - "modified": "2026-08-29T08:44:26Z", + "modified": "2026-09-04T08:51:51Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cruft-CVE-2026-76221.json b/advisories/BREW-cruft-CVE-2026-76221.json index c2a31c03cf..903994999d 100644 --- a/advisories/BREW-cruft-CVE-2026-76221.json +++ b/advisories/BREW-cruft-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cruft-CVE-2026-76221", "published": "2026-08-20T08:44:24Z", - "modified": "2026-08-20T08:44:24Z", + "modified": "2026-09-04T08:52:00Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cruft-CVE-2026-76222.json b/advisories/BREW-cruft-CVE-2026-76222.json index a1d3019e1d..300dbbb219 100644 --- a/advisories/BREW-cruft-CVE-2026-76222.json +++ b/advisories/BREW-cruft-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cruft-CVE-2026-76222", "published": "2026-08-20T08:44:24Z", - "modified": "2026-08-20T08:44:24Z", + "modified": "2026-09-04T08:52:00Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cruft-CVE-2026-78675.json b/advisories/BREW-cruft-CVE-2026-78675.json new file mode 100644 index 0000000000..5951a8fd1d --- /dev/null +++ b/advisories/BREW-cruft-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cruft-CVE-2026-78675", + "published": "2026-09-04T08:52:00Z", + "modified": "2026-09-04T08:52:00Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cruft", + "purl": "pkg:brew/cruft" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-cruft-CVE-2026-78676.json b/advisories/BREW-cruft-CVE-2026-78676.json new file mode 100644 index 0000000000..afe3bc65c4 --- /dev/null +++ b/advisories/BREW-cruft-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cruft-CVE-2026-78676", + "published": "2026-09-04T08:52:00Z", + "modified": "2026-09-04T08:52:00Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cruft", + "purl": "pkg:brew/cruft" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-cruft-CVE-2026-78677.json b/advisories/BREW-cruft-CVE-2026-78677.json new file mode 100644 index 0000000000..b19f0c1142 --- /dev/null +++ b/advisories/BREW-cruft-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cruft-CVE-2026-78677", + "published": "2026-09-04T08:52:00Z", + "modified": "2026-09-04T08:52:00Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cruft", + "purl": "pkg:brew/cruft" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-cruft-CVE-2026-78678.json b/advisories/BREW-cruft-CVE-2026-78678.json new file mode 100644 index 0000000000..249c68ac14 --- /dev/null +++ b/advisories/BREW-cruft-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cruft-CVE-2026-78678", + "published": "2026-09-04T08:52:00Z", + "modified": "2026-09-04T08:52:00Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cruft", + "purl": "pkg:brew/cruft" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-cruft-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-cruft-GHSA-hmq2-w58f-27jc.json index 881e8d745b..f9b9d3ecf3 100644 --- a/advisories/BREW-cruft-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-cruft-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cruft-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-29T08:44:34Z", + "modified": "2026-09-04T08:52:00Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cruft-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-cruft-GHSA-jm78-9fvv-mhgr.json index 33c2b47a22..4fa59ec1ac 100644 --- a/advisories/BREW-cruft-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-cruft-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cruft-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-29T08:44:34Z", + "modified": "2026-09-04T08:52:00Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cycode-CVE-2026-76221.json b/advisories/BREW-cycode-CVE-2026-76221.json index 84165434cc..b8241c53b2 100644 --- a/advisories/BREW-cycode-CVE-2026-76221.json +++ b/advisories/BREW-cycode-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cycode-CVE-2026-76221", "published": "2026-08-20T08:45:02Z", - "modified": "2026-09-02T08:51:49Z", + "modified": "2026-09-04T08:54:03Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cycode-CVE-2026-76222.json b/advisories/BREW-cycode-CVE-2026-76222.json index 55ef40708e..d5c8c10b89 100644 --- a/advisories/BREW-cycode-CVE-2026-76222.json +++ b/advisories/BREW-cycode-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cycode-CVE-2026-76222", "published": "2026-08-20T08:45:02Z", - "modified": "2026-09-02T08:51:49Z", + "modified": "2026-09-04T08:54:03Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cycode-CVE-2026-78675.json b/advisories/BREW-cycode-CVE-2026-78675.json new file mode 100644 index 0000000000..0ad48dad25 --- /dev/null +++ b/advisories/BREW-cycode-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cycode-CVE-2026-78675", + "published": "2026-09-04T08:54:09Z", + "modified": "2026-09-04T08:54:09Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cycode", + "purl": "pkg:brew/cycode" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.19.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-cycode-CVE-2026-78676.json b/advisories/BREW-cycode-CVE-2026-78676.json new file mode 100644 index 0000000000..39a5a77d99 --- /dev/null +++ b/advisories/BREW-cycode-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cycode-CVE-2026-78676", + "published": "2026-09-04T08:54:09Z", + "modified": "2026-09-04T08:54:09Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cycode", + "purl": "pkg:brew/cycode" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.19.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-cycode-CVE-2026-78677.json b/advisories/BREW-cycode-CVE-2026-78677.json new file mode 100644 index 0000000000..16eaefda95 --- /dev/null +++ b/advisories/BREW-cycode-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cycode-CVE-2026-78677", + "published": "2026-09-04T08:54:09Z", + "modified": "2026-09-04T08:54:09Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cycode", + "purl": "pkg:brew/cycode" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.19.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-cycode-CVE-2026-78678.json b/advisories/BREW-cycode-CVE-2026-78678.json new file mode 100644 index 0000000000..c2f86f7ebc --- /dev/null +++ b/advisories/BREW-cycode-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cycode-CVE-2026-78678", + "published": "2026-09-04T08:54:09Z", + "modified": "2026-09-04T08:54:09Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cycode", + "purl": "pkg:brew/cycode" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.19.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-cycode-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-cycode-GHSA-hmq2-w58f-27jc.json index 00bdbe5ea7..8bec21cd5c 100644 --- a/advisories/BREW-cycode-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-cycode-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cycode-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:42:07Z", - "modified": "2026-09-02T08:51:49Z", + "modified": "2026-09-04T08:54:03Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cycode-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-cycode-GHSA-jm78-9fvv-mhgr.json index 5426cdf23d..9a5032e724 100644 --- a/advisories/BREW-cycode-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-cycode-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cycode-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:42:07Z", - "modified": "2026-09-02T08:51:49Z", + "modified": "2026-09-04T08:54:03Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-djlint-CVE-2026-7246.json b/advisories/BREW-djlint-CVE-2026-7246.json index adf396a7ad..3db2fe6448 100644 --- a/advisories/BREW-djlint-CVE-2026-7246.json +++ b/advisories/BREW-djlint-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-djlint-CVE-2026-7246", "published": "2026-08-13T16:42:58Z", - "modified": "2026-08-13T16:42:58Z", + "modified": "2026-09-04T08:55:04Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-dstack-CVE-2026-76221.json b/advisories/BREW-dstack-CVE-2026-76221.json index a2e5777edb..6129693895 100644 --- a/advisories/BREW-dstack-CVE-2026-76221.json +++ b/advisories/BREW-dstack-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2026-76221", "published": "2026-08-20T08:46:26Z", - "modified": "2026-08-29T08:47:36Z", + "modified": "2026-09-04T08:56:04Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dstack-CVE-2026-76222.json b/advisories/BREW-dstack-CVE-2026-76222.json index 74b23657ff..d3a4df94fb 100644 --- a/advisories/BREW-dstack-CVE-2026-76222.json +++ b/advisories/BREW-dstack-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2026-76222", "published": "2026-08-20T08:46:26Z", - "modified": "2026-08-29T08:47:36Z", + "modified": "2026-09-04T08:56:04Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dstack-CVE-2026-78675.json b/advisories/BREW-dstack-CVE-2026-78675.json new file mode 100644 index 0000000000..1b726b461d --- /dev/null +++ b/advisories/BREW-dstack-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dstack-CVE-2026-78675", + "published": "2026-09-04T08:56:11Z", + "modified": "2026-09-04T08:56:11Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dstack", + "purl": "pkg:brew/dstack" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-dstack-CVE-2026-78676.json b/advisories/BREW-dstack-CVE-2026-78676.json new file mode 100644 index 0000000000..1aef1e1c58 --- /dev/null +++ b/advisories/BREW-dstack-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dstack-CVE-2026-78676", + "published": "2026-09-04T08:56:11Z", + "modified": "2026-09-04T08:56:11Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dstack", + "purl": "pkg:brew/dstack" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-dstack-CVE-2026-78677.json b/advisories/BREW-dstack-CVE-2026-78677.json new file mode 100644 index 0000000000..883534d386 --- /dev/null +++ b/advisories/BREW-dstack-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dstack-CVE-2026-78677", + "published": "2026-09-04T08:56:11Z", + "modified": "2026-09-04T08:56:11Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dstack", + "purl": "pkg:brew/dstack" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-dstack-CVE-2026-78678.json b/advisories/BREW-dstack-CVE-2026-78678.json new file mode 100644 index 0000000000..1157a19da9 --- /dev/null +++ b/advisories/BREW-dstack-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dstack-CVE-2026-78678", + "published": "2026-09-04T08:56:11Z", + "modified": "2026-09-04T08:56:11Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dstack", + "purl": "pkg:brew/dstack" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-dstack-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-dstack-GHSA-hmq2-w58f-27jc.json index a9cd069b62..a050161021 100644 --- a/advisories/BREW-dstack-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-dstack-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dstack-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-29T08:47:36Z", + "modified": "2026-09-04T08:56:04Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dstack-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-dstack-GHSA-jm78-9fvv-mhgr.json index e0bd791f2c..38a6a97f94 100644 --- a/advisories/BREW-dstack-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-dstack-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dstack-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-29T08:47:36Z", + "modified": "2026-09-04T08:56:04Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dvc-CVE-2026-76221.json b/advisories/BREW-dvc-CVE-2026-76221.json index caeef48953..94bfa2c34c 100644 --- a/advisories/BREW-dvc-CVE-2026-76221.json +++ b/advisories/BREW-dvc-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dvc-CVE-2026-76221", "published": "2026-08-20T08:46:31Z", - "modified": "2026-08-20T08:46:31Z", + "modified": "2026-09-04T08:56:18Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dvc-CVE-2026-76222.json b/advisories/BREW-dvc-CVE-2026-76222.json index de7188520f..ec33042ead 100644 --- a/advisories/BREW-dvc-CVE-2026-76222.json +++ b/advisories/BREW-dvc-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dvc-CVE-2026-76222", "published": "2026-08-20T08:46:31Z", - "modified": "2026-08-20T08:46:31Z", + "modified": "2026-09-04T08:56:18Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dvc-CVE-2026-78675.json b/advisories/BREW-dvc-CVE-2026-78675.json new file mode 100644 index 0000000000..d19275af21 --- /dev/null +++ b/advisories/BREW-dvc-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dvc-CVE-2026-78675", + "published": "2026-09-04T08:56:18Z", + "modified": "2026-09-04T08:56:18Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dvc", + "purl": "pkg:brew/dvc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-dvc-CVE-2026-78676.json b/advisories/BREW-dvc-CVE-2026-78676.json new file mode 100644 index 0000000000..08ce8052bc --- /dev/null +++ b/advisories/BREW-dvc-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dvc-CVE-2026-78676", + "published": "2026-09-04T08:56:18Z", + "modified": "2026-09-04T08:56:18Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dvc", + "purl": "pkg:brew/dvc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-dvc-CVE-2026-78677.json b/advisories/BREW-dvc-CVE-2026-78677.json new file mode 100644 index 0000000000..e900067174 --- /dev/null +++ b/advisories/BREW-dvc-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dvc-CVE-2026-78677", + "published": "2026-09-04T08:56:18Z", + "modified": "2026-09-04T08:56:18Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dvc", + "purl": "pkg:brew/dvc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-dvc-CVE-2026-78678.json b/advisories/BREW-dvc-CVE-2026-78678.json new file mode 100644 index 0000000000..7b853f4c23 --- /dev/null +++ b/advisories/BREW-dvc-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dvc-CVE-2026-78678", + "published": "2026-09-04T08:56:18Z", + "modified": "2026-09-04T08:56:18Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dvc", + "purl": "pkg:brew/dvc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-dvc-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-dvc-GHSA-hmq2-w58f-27jc.json index 57e3644ded..e9a97e8e8f 100644 --- a/advisories/BREW-dvc-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-dvc-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dvc-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:44:03Z", - "modified": "2026-08-29T08:47:42Z", + "modified": "2026-09-04T08:56:18Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dvc-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-dvc-GHSA-jm78-9fvv-mhgr.json index 69a58e34f6..eef483faf9 100644 --- a/advisories/BREW-dvc-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-dvc-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dvc-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:44:03Z", - "modified": "2026-08-29T08:47:42Z", + "modified": "2026-09-04T08:56:18Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-esptool-CVE-2015-8557.json b/advisories/BREW-esptool-CVE-2015-8557.json index 2bfc83b039..850ceed084 100644 --- a/advisories/BREW-esptool-CVE-2015-8557.json +++ b/advisories/BREW-esptool-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2015-8557", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esptool-CVE-2018-1000518.json b/advisories/BREW-esptool-CVE-2018-1000518.json new file mode 100644 index 0000000000..c0a07bf906 --- /dev/null +++ b/advisories/BREW-esptool-CVE-2018-1000518.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-esptool-CVE-2018-1000518", + "published": "2026-09-04T08:57:54Z", + "modified": "2026-09-04T08:57:54Z", + "upstream": [ + "GHSA-6g87-ff9q-v847", + "CVE-2018-1000518", + "PYSEC-2018-79" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "esptool", + "purl": "pkg:brew/esptool" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.0", + "resource": "websockets", + "resource_purl": "pkg:pypi/websockets@17.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "17.1", + "key": "pkg:pypi/websockets@17.1", + "resource": "websockets" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "17.1", + "key": "pkg:pypi/websockets@17.1", + "resource": "websockets" + } + ] + }, + "summary": "websockets is vulnerable to denial of service by memory exhaustion", + "details": "The Python websockets library version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appears to be exploitable via sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in version 5.0", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000518" + }, + { + "type": "WEB", + "url": "https://github.com/aaugustin/websockets/pull/407" + }, + { + "type": "PACKAGE", + "url": "https://github.com/aaugustin/websockets" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/websockets/PYSEC-2018-79.yaml" + } + ] +} diff --git a/advisories/BREW-esptool-CVE-2021-20270.json b/advisories/BREW-esptool-CVE-2021-20270.json index 2dc4331834..57b57bde5c 100644 --- a/advisories/BREW-esptool-CVE-2021-20270.json +++ b/advisories/BREW-esptool-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2021-20270", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esptool-CVE-2021-27291.json b/advisories/BREW-esptool-CVE-2021-27291.json index 2bc4e6b385..180dc2e020 100644 --- a/advisories/BREW-esptool-CVE-2021-27291.json +++ b/advisories/BREW-esptool-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2021-27291", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esptool-CVE-2021-33880.json b/advisories/BREW-esptool-CVE-2021-33880.json new file mode 100644 index 0000000000..356a11c766 --- /dev/null +++ b/advisories/BREW-esptool-CVE-2021-33880.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-esptool-CVE-2021-33880", + "published": "2026-09-04T08:57:54Z", + "modified": "2026-09-04T08:57:54Z", + "upstream": [ + "GHSA-8ch4-58qp-g3mp", + "CVE-2021-33880", + "PYSEC-2021-95" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "esptool", + "purl": "pkg:brew/esptool" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "9.1", + "resource": "websockets", + "resource_purl": "pkg:pypi/websockets@17.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "17.1", + "key": "pkg:pypi/websockets@17.1", + "resource": "websockets" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "17.1", + "key": "pkg:pypi/websockets@17.1", + "resource": "websockets" + } + ] + }, + "summary": "Observable Timing Discrepancy in aaugustin websockets library", + "details": "The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33880" + }, + { + "type": "WEB", + "url": "https://github.com/aaugustin/websockets/commit/547a26b685d08cac0aa64e5e65f7867ac0ea9bc0" + }, + { + "type": "WEB", + "url": "https://github.com/aaugustin/websockets" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/websockets/PYSEC-2021-95.yaml" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujan2022.html" + } + ] +} diff --git a/advisories/BREW-esptool-CVE-2022-40896.json b/advisories/BREW-esptool-CVE-2022-40896.json index a499412480..4a9857aeba 100644 --- a/advisories/BREW-esptool-CVE-2022-40896.json +++ b/advisories/BREW-esptool-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2022-40896", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esptool-CVE-2023-46894.json b/advisories/BREW-esptool-CVE-2023-46894.json index cb9256bdaf..55f31b7d5b 100644 --- a/advisories/BREW-esptool-CVE-2023-46894.json +++ b/advisories/BREW-esptool-CVE-2023-46894.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2023-46894", "published": "2026-08-13T16:45:08Z", - "modified": "2026-09-03T08:57:54Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-3f38-96qm-r3fw", "CVE-2023-46894" @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "esptool", - "subject_version": "5.3.1", - "key": "pkg:pypi/esptool@5.3.1" + "subject_version": "5.4.0", + "key": "pkg:pypi/esptool@5.4.0" }, { "strategy": "distro", @@ -55,8 +55,8 @@ "strategy": "distro", "ecosystem": "PyPI", "name": "esptool", - "subject_version": "5.3.1", - "key": "upstream:pkg:pypi/esptool@5.3.1" + "subject_version": "5.4.0", + "key": "upstream:pkg:pypi/esptool@5.4.0" } ] }, diff --git a/advisories/BREW-esptool-CVE-2026-4539.json b/advisories/BREW-esptool-CVE-2026-4539.json index 2472fff884..33a9181c8e 100644 --- a/advisories/BREW-esptool-CVE-2026-4539.json +++ b/advisories/BREW-esptool-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2026-4539", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esptool-CVE-2026-7246.json b/advisories/BREW-esptool-CVE-2026-7246.json index 7c0abe32d5..b872eb9070 100644 --- a/advisories/BREW-esptool-CVE-2026-7246.json +++ b/advisories/BREW-esptool-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2026-7246", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-fastmcp-CVE-2025-62800.json b/advisories/BREW-fastmcp-CVE-2025-62800.json index f5e27368a5..c6fe711138 100644 --- a/advisories/BREW-fastmcp-CVE-2025-62800.json +++ b/advisories/BREW-fastmcp-CVE-2025-62800.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2025-62800", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-mxxr-jv3v-6pgc", "CVE-2025-62800", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-CVE-2025-62801.json b/advisories/BREW-fastmcp-CVE-2025-62801.json index 26975dc366..5a8b9f0f39 100644 --- a/advisories/BREW-fastmcp-CVE-2025-62801.json +++ b/advisories/BREW-fastmcp-CVE-2025-62801.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2025-62801", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-rj5c-58rq-j5g5", "CVE-2025-62801", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-CVE-2025-64340.json b/advisories/BREW-fastmcp-CVE-2025-64340.json index 70604579cd..d54c373d4f 100644 --- a/advisories/BREW-fastmcp-CVE-2025-64340.json +++ b/advisories/BREW-fastmcp-CVE-2025-64340.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2025-64340", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-m8x7-r2rg-vh5g", "CVE-2025-64340", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-CVE-2025-69196.json b/advisories/BREW-fastmcp-CVE-2025-69196.json index 77383c72a9..5411b02158 100644 --- a/advisories/BREW-fastmcp-CVE-2025-69196.json +++ b/advisories/BREW-fastmcp-CVE-2025-69196.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2025-69196", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-5h2m-4q8j-pqpj", "CVE-2025-69196", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-CVE-2026-27124.json b/advisories/BREW-fastmcp-CVE-2026-27124.json index be068a63a9..d0b6945dc0 100644 --- a/advisories/BREW-fastmcp-CVE-2026-27124.json +++ b/advisories/BREW-fastmcp-CVE-2026-27124.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2026-27124", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-rww4-4w9c-7733", "CVE-2026-27124", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-CVE-2026-32871.json b/advisories/BREW-fastmcp-CVE-2026-32871.json index 30e94f7f8e..24648a9a1c 100644 --- a/advisories/BREW-fastmcp-CVE-2026-32871.json +++ b/advisories/BREW-fastmcp-CVE-2026-32871.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2026-32871", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-vv7q-7jx5-f767", "CVE-2026-32871", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-GHSA-c2jp-c369-7pvx.json b/advisories/BREW-fastmcp-GHSA-c2jp-c369-7pvx.json index 62a4f5cbce..6fadf68cd7 100644 --- a/advisories/BREW-fastmcp-GHSA-c2jp-c369-7pvx.json +++ b/advisories/BREW-fastmcp-GHSA-c2jp-c369-7pvx.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-GHSA-c2jp-c369-7pvx", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-c2jp-c369-7pvx" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-GHSA-rcfx-77hg-w2wv.json b/advisories/BREW-fastmcp-GHSA-rcfx-77hg-w2wv.json index 453bcdcfed..6cc20f7a32 100644 --- a/advisories/BREW-fastmcp-GHSA-rcfx-77hg-w2wv.json +++ b/advisories/BREW-fastmcp-GHSA-rcfx-77hg-w2wv.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-GHSA-rcfx-77hg-w2wv", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-rcfx-77hg-w2wv" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fdroidserver-CVE-2026-76221.json b/advisories/BREW-fdroidserver-CVE-2026-76221.json index b908ee2fa4..0e91216360 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76221.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76221", "published": "2026-08-20T08:51:09Z", - "modified": "2026-08-20T08:51:09Z", + "modified": "2026-09-04T08:59:24Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-76222.json b/advisories/BREW-fdroidserver-CVE-2026-76222.json index 5f581b962e..4e4c5b0944 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76222.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76222", "published": "2026-08-20T08:51:09Z", - "modified": "2026-08-20T08:51:09Z", + "modified": "2026-09-04T08:59:24Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-78675.json b/advisories/BREW-fdroidserver-CVE-2026-78675.json new file mode 100644 index 0000000000..a4d0858f0b --- /dev/null +++ b/advisories/BREW-fdroidserver-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-fdroidserver-CVE-2026-78675", + "published": "2026-09-04T08:59:24Z", + "modified": "2026-09-04T08:59:24Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "fdroidserver", + "purl": "pkg:brew/fdroidserver" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-fdroidserver-CVE-2026-78676.json b/advisories/BREW-fdroidserver-CVE-2026-78676.json new file mode 100644 index 0000000000..939f46111c --- /dev/null +++ b/advisories/BREW-fdroidserver-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-fdroidserver-CVE-2026-78676", + "published": "2026-09-04T08:59:24Z", + "modified": "2026-09-04T08:59:24Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "fdroidserver", + "purl": "pkg:brew/fdroidserver" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-fdroidserver-CVE-2026-78677.json b/advisories/BREW-fdroidserver-CVE-2026-78677.json new file mode 100644 index 0000000000..331ac931a4 --- /dev/null +++ b/advisories/BREW-fdroidserver-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-fdroidserver-CVE-2026-78677", + "published": "2026-09-04T08:59:24Z", + "modified": "2026-09-04T08:59:24Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "fdroidserver", + "purl": "pkg:brew/fdroidserver" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-fdroidserver-CVE-2026-78678.json b/advisories/BREW-fdroidserver-CVE-2026-78678.json new file mode 100644 index 0000000000..bea77d38f9 --- /dev/null +++ b/advisories/BREW-fdroidserver-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-fdroidserver-CVE-2026-78678", + "published": "2026-09-04T08:59:24Z", + "modified": "2026-09-04T08:59:24Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "fdroidserver", + "purl": "pkg:brew/fdroidserver" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-fdroidserver-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-fdroidserver-GHSA-hmq2-w58f-27jc.json index eb67f2dcc4..83db87b09e 100644 --- a/advisories/BREW-fdroidserver-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-fdroidserver-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-29T08:50:16Z", + "modified": "2026-09-04T08:59:24Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-fdroidserver-GHSA-jm78-9fvv-mhgr.json index 386f2d695d..290caf217f 100644 --- a/advisories/BREW-fdroidserver-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-fdroidserver-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-29T08:50:16Z", + "modified": "2026-09-04T08:59:24Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-firebase-cli-CVE-2024-4128.json b/advisories/BREW-firebase-cli-CVE-2024-4128.json index e60012a31d..1dc90d783b 100644 --- a/advisories/BREW-firebase-cli-CVE-2024-4128.json +++ b/advisories/BREW-firebase-cli-CVE-2024-4128.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-firebase-cli-CVE-2024-4128", "published": "2026-08-13T16:47:26Z", - "modified": "2026-08-29T08:51:11Z", + "modified": "2026-09-04T09:00:28Z", "upstream": [ "GHSA-rcm2-22f3-pqv3", "CVE-2024-4128", @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "firebase-tools", - "subject_version": "15.28.2", - "key": "pkg:npm/firebase-tools@15.28.2" + "subject_version": "15.29.0", + "key": "pkg:npm/firebase-tools@15.29.0" } ] }, diff --git a/advisories/BREW-gitup-CVE-2026-76221.json b/advisories/BREW-gitup-CVE-2026-76221.json index 4274473993..b3c64c0cbe 100644 --- a/advisories/BREW-gitup-CVE-2026-76221.json +++ b/advisories/BREW-gitup-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-gitup-CVE-2026-76221", "published": "2026-08-20T08:55:17Z", - "modified": "2026-08-20T08:55:17Z", + "modified": "2026-09-04T09:04:14Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-gitup-CVE-2026-76222.json b/advisories/BREW-gitup-CVE-2026-76222.json index 6d65d4228b..57aa57490a 100644 --- a/advisories/BREW-gitup-CVE-2026-76222.json +++ b/advisories/BREW-gitup-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-gitup-CVE-2026-76222", "published": "2026-08-20T08:55:17Z", - "modified": "2026-08-20T08:55:17Z", + "modified": "2026-09-04T09:04:14Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-gitup-CVE-2026-78675.json b/advisories/BREW-gitup-CVE-2026-78675.json new file mode 100644 index 0000000000..51d45234f3 --- /dev/null +++ b/advisories/BREW-gitup-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gitup-CVE-2026-78675", + "published": "2026-09-04T09:04:14Z", + "modified": "2026-09-04T09:04:14Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gitup", + "purl": "pkg:brew/gitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-gitup-CVE-2026-78676.json b/advisories/BREW-gitup-CVE-2026-78676.json new file mode 100644 index 0000000000..49a5fda800 --- /dev/null +++ b/advisories/BREW-gitup-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gitup-CVE-2026-78676", + "published": "2026-09-04T09:04:14Z", + "modified": "2026-09-04T09:04:14Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gitup", + "purl": "pkg:brew/gitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-gitup-CVE-2026-78677.json b/advisories/BREW-gitup-CVE-2026-78677.json new file mode 100644 index 0000000000..5b7754a96f --- /dev/null +++ b/advisories/BREW-gitup-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gitup-CVE-2026-78677", + "published": "2026-09-04T09:04:14Z", + "modified": "2026-09-04T09:04:14Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gitup", + "purl": "pkg:brew/gitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-gitup-CVE-2026-78678.json b/advisories/BREW-gitup-CVE-2026-78678.json new file mode 100644 index 0000000000..c1a8b85d30 --- /dev/null +++ b/advisories/BREW-gitup-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gitup-CVE-2026-78678", + "published": "2026-09-04T09:04:14Z", + "modified": "2026-09-04T09:04:14Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gitup", + "purl": "pkg:brew/gitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-gitup-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-gitup-GHSA-hmq2-w58f-27jc.json index 0512e779b1..31d5c6bafd 100644 --- a/advisories/BREW-gitup-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-gitup-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-gitup-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:51:23Z", - "modified": "2026-08-29T08:55:01Z", + "modified": "2026-09-04T09:04:14Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-gitup-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-gitup-GHSA-jm78-9fvv-mhgr.json index 97a82142fe..2ec1c1bffb 100644 --- a/advisories/BREW-gitup-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-gitup-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-gitup-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:51:23Z", - "modified": "2026-08-29T08:55:01Z", + "modified": "2026-09-04T09:04:14Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-glances-CVE-2024-33663.json b/advisories/BREW-glances-CVE-2024-33663.json index e99b774adc..f0d60b3a9e 100644 --- a/advisories/BREW-glances-CVE-2024-33663.json +++ b/advisories/BREW-glances-CVE-2024-33663.json @@ -2,11 +2,12 @@ "schema_version": "1.7.3", "id": "BREW-glances-CVE-2024-33663", "published": "2026-08-13T16:51:23Z", - "modified": "2026-08-13T16:51:23Z", + "modified": "2026-09-04T09:04:14Z", "upstream": [ "GHSA-6c5p-j8vq-pqhj", "CVE-2024-33663", - "PYSEC-2024-232" + "PYSEC-2024-232", + "CVE-2026-85394" ], "affected": [ { diff --git a/advisories/BREW-gptline-CVE-2026-62384.json b/advisories/BREW-gptline-CVE-2026-62384.json new file mode 100644 index 0000000000..8237cce35a --- /dev/null +++ b/advisories/BREW-gptline-CVE-2026-62384.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gptline-CVE-2026-62384", + "published": "2026-09-04T09:08:36Z", + "modified": "2026-09-04T09:08:36Z", + "upstream": [ + "PYSEC-2026-3789", + "CVE-2026-62384", + "GHSA-f833-7jw8-xwrv" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gptline", + "purl": "pkg:brew/gptline" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.8_23" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.10.2", + "resource": "nltk", + "resource_purl": "pkg:pypi/nltk@3.10.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + } + ] + }, + "details": "NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/nltk-framenetcorpusreader-symlink-sandbox-bypass-before" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv" + } + ] +} diff --git a/advisories/BREW-gptline-CVE-2026-71514.json b/advisories/BREW-gptline-CVE-2026-71514.json index 7844f14f5f..6a709384e2 100644 --- a/advisories/BREW-gptline-CVE-2026-71514.json +++ b/advisories/BREW-gptline-CVE-2026-71514.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-gptline-CVE-2026-71514", "published": "2026-09-03T09:08:38Z", - "modified": "2026-09-03T09:08:38Z", + "modified": "2026-09-04T09:07:33Z", "upstream": [ "GHSA-cv22-g7mw-8v73", - "CVE-2026-71514" + "CVE-2026-71514", + "PYSEC-2026-3790" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-harlequin-CVE-2026-7246.json b/advisories/BREW-harlequin-CVE-2026-7246.json index af872cbe9b..1e05f0bcd1 100644 --- a/advisories/BREW-harlequin-CVE-2026-7246.json +++ b/advisories/BREW-harlequin-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-harlequin-CVE-2026-7246", "published": "2026-08-13T16:55:40Z", - "modified": "2026-08-17T17:14:34Z", + "modified": "2026-09-04T09:10:20Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-jiratui-CVE-2026-76221.json b/advisories/BREW-jiratui-CVE-2026-76221.json index 7d1abe5856..f23d52dc45 100644 --- a/advisories/BREW-jiratui-CVE-2026-76221.json +++ b/advisories/BREW-jiratui-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-jiratui-CVE-2026-76221", "published": "2026-08-20T09:04:13Z", - "modified": "2026-08-30T09:08:48Z", + "modified": "2026-09-04T09:15:06Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jiratui-CVE-2026-76222.json b/advisories/BREW-jiratui-CVE-2026-76222.json index 2de8b4dbc5..6d6cc0f7f9 100644 --- a/advisories/BREW-jiratui-CVE-2026-76222.json +++ b/advisories/BREW-jiratui-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-jiratui-CVE-2026-76222", "published": "2026-08-20T09:04:13Z", - "modified": "2026-08-30T09:08:48Z", + "modified": "2026-09-04T09:15:06Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jiratui-CVE-2026-78675.json b/advisories/BREW-jiratui-CVE-2026-78675.json new file mode 100644 index 0000000000..a1b00e89ba --- /dev/null +++ b/advisories/BREW-jiratui-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-jiratui-CVE-2026-78675", + "published": "2026-09-04T09:16:19Z", + "modified": "2026-09-04T09:16:19Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "jiratui", + "purl": "pkg:brew/jiratui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-jiratui-CVE-2026-78676.json b/advisories/BREW-jiratui-CVE-2026-78676.json new file mode 100644 index 0000000000..5b2aa99937 --- /dev/null +++ b/advisories/BREW-jiratui-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-jiratui-CVE-2026-78676", + "published": "2026-09-04T09:16:19Z", + "modified": "2026-09-04T09:16:19Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "jiratui", + "purl": "pkg:brew/jiratui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-jiratui-CVE-2026-78677.json b/advisories/BREW-jiratui-CVE-2026-78677.json new file mode 100644 index 0000000000..6bed1d8f11 --- /dev/null +++ b/advisories/BREW-jiratui-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-jiratui-CVE-2026-78677", + "published": "2026-09-04T09:16:19Z", + "modified": "2026-09-04T09:16:19Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "jiratui", + "purl": "pkg:brew/jiratui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-jiratui-CVE-2026-78678.json b/advisories/BREW-jiratui-CVE-2026-78678.json new file mode 100644 index 0000000000..f5b6cde576 --- /dev/null +++ b/advisories/BREW-jiratui-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-jiratui-CVE-2026-78678", + "published": "2026-09-04T09:16:19Z", + "modified": "2026-09-04T09:16:19Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "jiratui", + "purl": "pkg:brew/jiratui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-jiratui-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-jiratui-GHSA-hmq2-w58f-27jc.json index c89a478ede..9690f37b5b 100644 --- a/advisories/BREW-jiratui-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-jiratui-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-jiratui-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:00:58Z", - "modified": "2026-08-30T09:08:48Z", + "modified": "2026-09-04T09:15:06Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jiratui-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-jiratui-GHSA-jm78-9fvv-mhgr.json index 8a8051824d..88a6846ecc 100644 --- a/advisories/BREW-jiratui-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-jiratui-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-jiratui-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:00:58Z", - "modified": "2026-08-30T09:08:48Z", + "modified": "2026-09-04T09:15:06Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-kimi-cli-CVE-2026-76221.json b/advisories/BREW-kimi-cli-CVE-2026-76221.json index d66f933eb8..ddd971171d 100644 --- a/advisories/BREW-kimi-cli-CVE-2026-76221.json +++ b/advisories/BREW-kimi-cli-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-kimi-cli-CVE-2026-76221", "published": "2026-08-20T09:04:48Z", - "modified": "2026-08-20T09:04:48Z", + "modified": "2026-09-04T09:18:03Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-kimi-cli-CVE-2026-76222.json b/advisories/BREW-kimi-cli-CVE-2026-76222.json index a3e6536097..8c7e03c5df 100644 --- a/advisories/BREW-kimi-cli-CVE-2026-76222.json +++ b/advisories/BREW-kimi-cli-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-kimi-cli-CVE-2026-76222", "published": "2026-08-20T09:04:48Z", - "modified": "2026-08-20T09:04:48Z", + "modified": "2026-09-04T09:18:03Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-kimi-cli-CVE-2026-78675.json b/advisories/BREW-kimi-cli-CVE-2026-78675.json new file mode 100644 index 0000000000..fde5f7ee30 --- /dev/null +++ b/advisories/BREW-kimi-cli-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-kimi-cli-CVE-2026-78675", + "published": "2026-09-04T09:18:03Z", + "modified": "2026-09-04T09:18:03Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "kimi-cli", + "purl": "pkg:brew/kimi-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.52" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-kimi-cli-CVE-2026-78676.json b/advisories/BREW-kimi-cli-CVE-2026-78676.json new file mode 100644 index 0000000000..837319687b --- /dev/null +++ b/advisories/BREW-kimi-cli-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-kimi-cli-CVE-2026-78676", + "published": "2026-09-04T09:18:03Z", + "modified": "2026-09-04T09:18:03Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "kimi-cli", + "purl": "pkg:brew/kimi-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.52" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-kimi-cli-CVE-2026-78677.json b/advisories/BREW-kimi-cli-CVE-2026-78677.json new file mode 100644 index 0000000000..4488b0e6e5 --- /dev/null +++ b/advisories/BREW-kimi-cli-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-kimi-cli-CVE-2026-78677", + "published": "2026-09-04T09:18:03Z", + "modified": "2026-09-04T09:18:03Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "kimi-cli", + "purl": "pkg:brew/kimi-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.52" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-kimi-cli-CVE-2026-78678.json b/advisories/BREW-kimi-cli-CVE-2026-78678.json new file mode 100644 index 0000000000..1a9caae3b6 --- /dev/null +++ b/advisories/BREW-kimi-cli-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-kimi-cli-CVE-2026-78678", + "published": "2026-09-04T09:18:03Z", + "modified": "2026-09-04T09:18:03Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "kimi-cli", + "purl": "pkg:brew/kimi-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.52" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-kimi-cli-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-kimi-cli-GHSA-hmq2-w58f-27jc.json index 01ebe2f45e..aa35b430bc 100644 --- a/advisories/BREW-kimi-cli-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-kimi-cli-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-kimi-cli-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:01:40Z", - "modified": "2026-08-29T09:06:02Z", + "modified": "2026-09-04T09:18:03Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-kimi-cli-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-kimi-cli-GHSA-jm78-9fvv-mhgr.json index 288582f5c0..8c618020c2 100644 --- a/advisories/BREW-kimi-cli-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-kimi-cli-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-kimi-cli-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:01:40Z", - "modified": "2026-08-29T09:06:02Z", + "modified": "2026-09-04T09:18:03Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-76221.json b/advisories/BREW-legit-CVE-2026-76221.json index a4e449a4cc..1e472d83e8 100644 --- a/advisories/BREW-legit-CVE-2026-76221.json +++ b/advisories/BREW-legit-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76221", "published": "2026-08-20T09:05:37Z", - "modified": "2026-08-20T09:05:37Z", + "modified": "2026-09-04T09:19:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-76222.json b/advisories/BREW-legit-CVE-2026-76222.json index 08bdf96d49..a08ad4ef30 100644 --- a/advisories/BREW-legit-CVE-2026-76222.json +++ b/advisories/BREW-legit-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76222", "published": "2026-08-20T09:05:37Z", - "modified": "2026-08-20T09:05:37Z", + "modified": "2026-09-04T09:19:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-78675.json b/advisories/BREW-legit-CVE-2026-78675.json new file mode 100644 index 0000000000..825005b102 --- /dev/null +++ b/advisories/BREW-legit-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-legit-CVE-2026-78675", + "published": "2026-09-04T09:19:02Z", + "modified": "2026-09-04T09:19:02Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "legit", + "purl": "pkg:brew/legit" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-legit-CVE-2026-78676.json b/advisories/BREW-legit-CVE-2026-78676.json new file mode 100644 index 0000000000..7b25336e59 --- /dev/null +++ b/advisories/BREW-legit-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-legit-CVE-2026-78676", + "published": "2026-09-04T09:19:02Z", + "modified": "2026-09-04T09:19:02Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "legit", + "purl": "pkg:brew/legit" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-legit-CVE-2026-78677.json b/advisories/BREW-legit-CVE-2026-78677.json new file mode 100644 index 0000000000..604139d89b --- /dev/null +++ b/advisories/BREW-legit-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-legit-CVE-2026-78677", + "published": "2026-09-04T09:19:02Z", + "modified": "2026-09-04T09:19:02Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "legit", + "purl": "pkg:brew/legit" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-legit-CVE-2026-78678.json b/advisories/BREW-legit-CVE-2026-78678.json new file mode 100644 index 0000000000..2a568332ba --- /dev/null +++ b/advisories/BREW-legit-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-legit-CVE-2026-78678", + "published": "2026-09-04T09:19:02Z", + "modified": "2026-09-04T09:19:02Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "legit", + "purl": "pkg:brew/legit" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-legit-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-legit-GHSA-hmq2-w58f-27jc.json index ef12dc9269..9d0a9ed313 100644 --- a/advisories/BREW-legit-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-legit-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:02:43Z", - "modified": "2026-08-29T09:06:59Z", + "modified": "2026-09-04T09:19:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-legit-GHSA-jm78-9fvv-mhgr.json index 64f921c08d..5a2efdd2c2 100644 --- a/advisories/BREW-legit-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-legit-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:02:43Z", - "modified": "2026-08-29T09:06:59Z", + "modified": "2026-09-04T09:19:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-llm-CVE-2026-31236.json b/advisories/BREW-llm-CVE-2026-31236.json index 8f426e700b..d1e30ea311 100644 --- a/advisories/BREW-llm-CVE-2026-31236.json +++ b/advisories/BREW-llm-CVE-2026-31236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-llm-CVE-2026-31236", "published": "2026-08-13T17:03:00Z", - "modified": "2026-09-03T09:21:28Z", + "modified": "2026-09-04T09:19:21Z", "upstream": [ "GHSA-g76p-4vg5-f4qh", "CVE-2026-31236", @@ -43,15 +43,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "llm", - "subject_version": "0.33", - "key": "pkg:pypi/llm@0.33" + "subject_version": "0.34", + "key": "pkg:pypi/llm@0.34" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "llm", - "subject_version": "0.33", - "key": "pkg:pypi/llm@0.33" + "subject_version": "0.34", + "key": "pkg:pypi/llm@0.34" } ] }, diff --git a/advisories/BREW-llm-CVE-2026-7246.json b/advisories/BREW-llm-CVE-2026-7246.json index f1b35be045..ab08d3af75 100644 --- a/advisories/BREW-llm-CVE-2026-7246.json +++ b/advisories/BREW-llm-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-llm-CVE-2026-7246", "published": "2026-08-13T17:03:00Z", - "modified": "2026-08-13T17:03:00Z", + "modified": "2026-09-04T09:19:21Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2009-3287.json b/advisories/BREW-mailcatcher-CVE-2009-3287.json index 31566b29b6..2c2b6f167a 100644 --- a/advisories/BREW-mailcatcher-CVE-2009-3287.json +++ b/advisories/BREW-mailcatcher-CVE-2009-3287.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2009-3287", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-j24p-r6wx-r79w", "CVE-2009-3287" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.4", "resource": "thin", - "resource_purl": "pkg:gem/thin@1.8.2" + "resource_purl": "pkg:gem/thin@2.0.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "thin", - "subject_version": "1.8.2", - "key": "pkg:gem/thin@1.8.2", + "subject_version": "2.0.1", + "key": "pkg:gem/thin@2.0.1", "resource": "thin" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2011-0739.json b/advisories/BREW-mailcatcher-CVE-2011-0739.json index de45daa13b..ab59126c38 100644 --- a/advisories/BREW-mailcatcher-CVE-2011-0739.json +++ b/advisories/BREW-mailcatcher-CVE-2011-0739.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2011-0739", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-cpjc-p7fc-j9xh", "CVE-2011-0739" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.15", "resource": "mail", - "resource_purl": "pkg:gem/mail@2.8.1" + "resource_purl": "pkg:gem/mail@2.9.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "mail", - "subject_version": "2.8.1", - "key": "pkg:gem/mail@2.8.1", + "subject_version": "2.9.1", + "key": "pkg:gem/mail@2.9.1", "resource": "mail" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2011-5036.json b/advisories/BREW-mailcatcher-CVE-2011-5036.json index 3bebe7466d..aa0944ddcf 100644 --- a/advisories/BREW-mailcatcher-CVE-2011-5036.json +++ b/advisories/BREW-mailcatcher-CVE-2011-5036.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2011-5036", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-v6j3-7jrw-hq2p", "CVE-2011-5036" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2012-2139.json b/advisories/BREW-mailcatcher-CVE-2012-2139.json index 31250d5d63..50fee3c33f 100644 --- a/advisories/BREW-mailcatcher-CVE-2012-2139.json +++ b/advisories/BREW-mailcatcher-CVE-2012-2139.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2012-2139", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-cj92-c4fj-w9c5", "CVE-2012-2139" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.4.4", "resource": "mail", - "resource_purl": "pkg:gem/mail@2.8.1" + "resource_purl": "pkg:gem/mail@2.9.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "mail", - "subject_version": "2.8.1", - "key": "pkg:gem/mail@2.8.1", + "subject_version": "2.9.1", + "key": "pkg:gem/mail@2.9.1", "resource": "mail" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2012-2140.json b/advisories/BREW-mailcatcher-CVE-2012-2140.json index 2eb241cda6..97229c15b6 100644 --- a/advisories/BREW-mailcatcher-CVE-2012-2140.json +++ b/advisories/BREW-mailcatcher-CVE-2012-2140.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2012-2140", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-rp63-jfmw-532w", "CVE-2012-2140" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.4.3", "resource": "mail", - "resource_purl": "pkg:gem/mail@2.8.1" + "resource_purl": "pkg:gem/mail@2.9.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "mail", - "subject_version": "2.8.1", - "key": "pkg:gem/mail@2.8.1", + "subject_version": "2.9.1", + "key": "pkg:gem/mail@2.9.1", "resource": "mail" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2012-6109.json b/advisories/BREW-mailcatcher-CVE-2012-6109.json index 9e4a03303f..c73cdda2ed 100644 --- a/advisories/BREW-mailcatcher-CVE-2012-6109.json +++ b/advisories/BREW-mailcatcher-CVE-2012-6109.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2012-6109", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-h77x-m5q8-c29h", "CVE-2012-6109" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.4.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2013-0183.json b/advisories/BREW-mailcatcher-CVE-2013-0183.json index 3bb4753877..672b460a98 100644 --- a/advisories/BREW-mailcatcher-CVE-2013-0183.json +++ b/advisories/BREW-mailcatcher-CVE-2013-0183.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2013-0183", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:20Z", "upstream": [ "GHSA-3pxh-h8hw-mj8w", "CVE-2013-0183" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.4.3", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2013-0184.json b/advisories/BREW-mailcatcher-CVE-2013-0184.json index a9866d2898..51b61ee71b 100644 --- a/advisories/BREW-mailcatcher-CVE-2013-0184.json +++ b/advisories/BREW-mailcatcher-CVE-2013-0184.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2013-0184", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-v882-ccj6-jc48", "CVE-2013-0184" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.4.4", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2013-0262.json b/advisories/BREW-mailcatcher-CVE-2013-0262.json index ac742ec52b..b09177d8bc 100644 --- a/advisories/BREW-mailcatcher-CVE-2013-0262.json +++ b/advisories/BREW-mailcatcher-CVE-2013-0262.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2013-0262", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-85r7-w5mv-c849", "CVE-2013-0262" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2013-0263.json b/advisories/BREW-mailcatcher-CVE-2013-0263.json index 8c5605d4f2..524a09e0bf 100644 --- a/advisories/BREW-mailcatcher-CVE-2013-0263.json +++ b/advisories/BREW-mailcatcher-CVE-2013-0263.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2013-0263", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-xc85-32mf-xpv8", "CVE-2013-0263" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2015-3225.json b/advisories/BREW-mailcatcher-CVE-2015-3225.json index a990f3f851..ca460f970f 100644 --- a/advisories/BREW-mailcatcher-CVE-2015-3225.json +++ b/advisories/BREW-mailcatcher-CVE-2015-3225.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2015-3225", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-rgr4-9jh5-j4j6", "CVE-2015-3225" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2015-9097.json b/advisories/BREW-mailcatcher-CVE-2015-9097.json index abfdbc19ee..41685ecee5 100644 --- a/advisories/BREW-mailcatcher-CVE-2015-9097.json +++ b/advisories/BREW-mailcatcher-CVE-2015-9097.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2015-9097", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-q86f-fmqf-qrf6", "CVE-2015-9097" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.5.5", "resource": "mail", - "resource_purl": "pkg:gem/mail@2.8.1" + "resource_purl": "pkg:gem/mail@2.9.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "mail", - "subject_version": "2.8.1", - "key": "pkg:gem/mail@2.8.1", + "subject_version": "2.9.1", + "key": "pkg:gem/mail@2.9.1", "resource": "mail" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2018-1000119.json b/advisories/BREW-mailcatcher-CVE-2018-1000119.json index afa4052319..d05f6e23d8 100644 --- a/advisories/BREW-mailcatcher-CVE-2018-1000119.json +++ b/advisories/BREW-mailcatcher-CVE-2018-1000119.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2018-1000119", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-688c-3x49-6rqj", "CVE-2018-1000119" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.0", "resource": "rack-protection", - "resource_purl": "pkg:gem/rack-protection@3.2.0" + "resource_purl": "pkg:gem/rack-protection@4.2.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack-protection", - "subject_version": "3.2.0", - "key": "pkg:gem/rack-protection@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/rack-protection@4.2.1", "resource": "rack-protection" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2018-11627.json b/advisories/BREW-mailcatcher-CVE-2018-11627.json index 007406e59a..efb287579f 100644 --- a/advisories/BREW-mailcatcher-CVE-2018-11627.json +++ b/advisories/BREW-mailcatcher-CVE-2018-11627.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2018-11627", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-mq35-wqvf-r23c", "CVE-2018-11627" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.2", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2018-16470.json b/advisories/BREW-mailcatcher-CVE-2018-16470.json index 25cc8a1028..c31161c4bd 100644 --- a/advisories/BREW-mailcatcher-CVE-2018-16470.json +++ b/advisories/BREW-mailcatcher-CVE-2018-16470.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2018-16470", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-hg78-4f6x-99wq", "CVE-2018-16470" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2018-16471.json b/advisories/BREW-mailcatcher-CVE-2018-16471.json index 95b49620d9..9396cd492a 100644 --- a/advisories/BREW-mailcatcher-CVE-2018-16471.json +++ b/advisories/BREW-mailcatcher-CVE-2018-16471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2018-16471", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-5r2p-j47h-mhpg", "CVE-2018-16471" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2018-7212.json b/advisories/BREW-mailcatcher-CVE-2018-7212.json index b2545a7ba5..267dc2304e 100644 --- a/advisories/BREW-mailcatcher-CVE-2018-7212.json +++ b/advisories/BREW-mailcatcher-CVE-2018-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2018-7212", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-h29f-7f56-j8wh", "CVE-2018-7212" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.1", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2019-16782.json b/advisories/BREW-mailcatcher-CVE-2019-16782.json index d80923bff6..5035f4adf8 100644 --- a/advisories/BREW-mailcatcher-CVE-2019-16782.json +++ b/advisories/BREW-mailcatcher-CVE-2019-16782.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2019-16782", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-hrqr-hxpp-chr3", "CVE-2019-16782" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.8", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2020-15133.json b/advisories/BREW-mailcatcher-CVE-2020-15133.json index ebe4e29d46..ab6493587f 100644 --- a/advisories/BREW-mailcatcher-CVE-2020-15133.json +++ b/advisories/BREW-mailcatcher-CVE-2020-15133.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2020-15133", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-2v5c-755p-p4gv", "CVE-2020-15133" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.0", "resource": "faye-websocket", - "resource_purl": "pkg:gem/faye-websocket@0.11.3" + "resource_purl": "pkg:gem/faye-websocket@0.12.0" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "faye-websocket", - "subject_version": "0.11.3", - "key": "pkg:gem/faye-websocket@0.11.3", + "subject_version": "0.12.0", + "key": "pkg:gem/faye-websocket@0.12.0", "resource": "faye-websocket" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2020-8161.json b/advisories/BREW-mailcatcher-CVE-2020-8161.json index ecdc4fadff..c1f8da3ade 100644 --- a/advisories/BREW-mailcatcher-CVE-2020-8161.json +++ b/advisories/BREW-mailcatcher-CVE-2020-8161.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2020-8161", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-5f9h-9pjv-v6j7", "CVE-2020-8161" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1.3", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2020-8184.json b/advisories/BREW-mailcatcher-CVE-2020-8184.json index b81541c2f4..eec8188849 100644 --- a/advisories/BREW-mailcatcher-CVE-2020-8184.json +++ b/advisories/BREW-mailcatcher-CVE-2020-8184.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2020-8184", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-j6w9-fv6q-3q52", "CVE-2020-8184" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.3", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2021-41817.json b/advisories/BREW-mailcatcher-CVE-2021-41817.json index 4f6d9f66e8..bdc44d6559 100644 --- a/advisories/BREW-mailcatcher-CVE-2021-41817.json +++ b/advisories/BREW-mailcatcher-CVE-2021-41817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2021-41817", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-qg54-694p-wgpp", "BIT-ruby-2021-41817", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.2.1", "resource": "date", - "resource_purl": "pkg:gem/date@3.3.4" + "resource_purl": "pkg:gem/date@3.5.1" } } ], @@ -47,8 +47,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "date", - "subject_version": "3.3.4", - "key": "pkg:gem/date@3.3.4", + "subject_version": "3.5.1", + "key": "pkg:gem/date@3.5.1", "resource": "date" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-29970.json b/advisories/BREW-mailcatcher-CVE-2022-29970.json index f625100b4e..51b619a49e 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-29970.json +++ b/advisories/BREW-mailcatcher-CVE-2022-29970.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-29970", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-qp49-3pvw-x4m5", "CVE-2022-29970" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.0", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-30122.json b/advisories/BREW-mailcatcher-CVE-2022-30122.json index 69c1a6a9ef..6ca04e4c2e 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-30122.json +++ b/advisories/BREW-mailcatcher-CVE-2022-30122.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-30122", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-hxqx-xwvh-44m2", "CVE-2022-30122" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.3.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-30123.json b/advisories/BREW-mailcatcher-CVE-2022-30123.json index 57d4b97e71..b5199404c3 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-30123.json +++ b/advisories/BREW-mailcatcher-CVE-2022-30123.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-30123", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-wq4h-7r42-5hrr", "CVE-2022-30123" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.3.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-44570.json b/advisories/BREW-mailcatcher-CVE-2022-44570.json index 9ce012ab35..b2ba942f3d 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-44570.json +++ b/advisories/BREW-mailcatcher-CVE-2022-44570.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-44570", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-65f5-mfpf-vfhj", "CVE-2022-44570" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.6.2", + "upstream_fixed_in": "3.0.4.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-44571.json b/advisories/BREW-mailcatcher-CVE-2022-44571.json index 8bfd456797..d869dde093 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-44571.json +++ b/advisories/BREW-mailcatcher-CVE-2022-44571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-44571", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-93pm-5p5f-3ghx", "CVE-2022-44571" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.6.1", + "upstream_fixed_in": "3.0.4.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-44572.json b/advisories/BREW-mailcatcher-CVE-2022-44572.json index eed157b7a7..b2e2b25d7c 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-44572.json +++ b/advisories/BREW-mailcatcher-CVE-2022-44572.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-44572", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-rqv2-275x-2jq5", "CVE-2022-44572" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.6.1", + "upstream_fixed_in": "3.0.4.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-45442.json b/advisories/BREW-mailcatcher-CVE-2022-45442.json index a3f5404952..1ccba08d34 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-45442.json +++ b/advisories/BREW-mailcatcher-CVE-2022-45442.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-45442", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-2x8x-jmrp-phxw", "CVE-2022-45442" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.0.4", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2023-27530.json b/advisories/BREW-mailcatcher-CVE-2023-27530.json index c1485122c0..b439b84015 100644 --- a/advisories/BREW-mailcatcher-CVE-2023-27530.json +++ b/advisories/BREW-mailcatcher-CVE-2023-27530.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2023-27530", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:20Z", "upstream": [ "GHSA-3h57-hmj3-gj3p", "CVE-2023-27530" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.6.3", + "upstream_fixed_in": "3.0.4.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2023-27539.json b/advisories/BREW-mailcatcher-CVE-2023-27539.json index 5a46162532..555729c3c3 100644 --- a/advisories/BREW-mailcatcher-CVE-2023-27539.json +++ b/advisories/BREW-mailcatcher-CVE-2023-27539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2023-27539", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-c6qg-cjj8-47qp", "CVE-2023-27539" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.6.4", + "upstream_fixed_in": "3.0.6.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2024-21510.json b/advisories/BREW-mailcatcher-CVE-2024-21510.json index 3f98c7477e..3c0970d72a 100644 --- a/advisories/BREW-mailcatcher-CVE-2024-21510.json +++ b/advisories/BREW-mailcatcher-CVE-2024-21510.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2024-21510", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-hxx2-7vcw-mqr3", "CVE-2024-21510" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "4.1.0", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2024-25126.json b/advisories/BREW-mailcatcher-CVE-2024-25126.json index 1349cc8fa9..ab97842a97 100644 --- a/advisories/BREW-mailcatcher-CVE-2024-25126.json +++ b/advisories/BREW-mailcatcher-CVE-2024-25126.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2024-25126", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:20Z", "upstream": [ "GHSA-22f2-v57c-j9cx", "CVE-2024-25126" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.8.1", + "upstream_fixed_in": "3.0.9.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2024-26141.json b/advisories/BREW-mailcatcher-CVE-2024-26141.json index 8288e04032..a5bbfef307 100644 --- a/advisories/BREW-mailcatcher-CVE-2024-26141.json +++ b/advisories/BREW-mailcatcher-CVE-2024-26141.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2024-26141", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-xj5v-6v4g-jfw6", "CVE-2024-26141" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.8.1", + "upstream_fixed_in": "3.0.9.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2024-26146.json b/advisories/BREW-mailcatcher-CVE-2024-26146.json index 43835d5bac..0993edeee5 100644 --- a/advisories/BREW-mailcatcher-CVE-2024-26146.json +++ b/advisories/BREW-mailcatcher-CVE-2024-26146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2024-26146", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-54rr-7fvw-6x8f", "CVE-2024-26146" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.8.1", + "upstream_fixed_in": "3.0.9.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-25184.json b/advisories/BREW-mailcatcher-CVE-2025-25184.json index 3bd4f649e1..57ec3157d8 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-25184.json +++ b/advisories/BREW-mailcatcher-CVE-2025-25184.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-25184", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-7g2v-jj9q-g3rg", "CVE-2025-25184" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.11", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.10", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-25186.json b/advisories/BREW-mailcatcher-CVE-2025-25186.json index 54b01de0a4..ab0e450473 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-25186.json +++ b/advisories/BREW-mailcatcher-CVE-2025-25186.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-25186", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-7fc5-f82f-cx69", "CVE-2025-25186" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.19", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.5.6", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-27111.json b/advisories/BREW-mailcatcher-CVE-2025-27111.json index 780a0d58a0..737c43bc25 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-27111.json +++ b/advisories/BREW-mailcatcher-CVE-2025-27111.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-27111", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-8cgq-6mh2-7j6v", "CVE-2025-27111" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.12", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.11", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-27610.json b/advisories/BREW-mailcatcher-CVE-2025-27610.json index 937c53930f..1e8aa3e0ed 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-27610.json +++ b/advisories/BREW-mailcatcher-CVE-2025-27610.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-27610", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-7wqh-767x-r66v", "CVE-2025-27610" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.13", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.12", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-32441.json b/advisories/BREW-mailcatcher-CVE-2025-32441.json index 8194d00434..f4182aaa6c 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-32441.json +++ b/advisories/BREW-mailcatcher-CVE-2025-32441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-32441", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-vpfw-47h7-xj4g", "CVE-2025-32441" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "2.2.14", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-43857.json b/advisories/BREW-mailcatcher-CVE-2025-43857.json index 4e3ed9a37d..a18dfebda2 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-43857.json +++ b/advisories/BREW-mailcatcher-CVE-2025-43857.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-43857", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-j3g3-5qv5-52mj", "CVE-2025-43857" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.20", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.5.7", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-46727.json b/advisories/BREW-mailcatcher-CVE-2025-46727.json index 5363c0325d..0d49a263a3 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-46727.json +++ b/advisories/BREW-mailcatcher-CVE-2025-46727.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-46727", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-gjh7-p2fx-99vx", "CVE-2025-46727" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.14", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.14", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-59830.json b/advisories/BREW-mailcatcher-CVE-2025-59830.json index 504eb10274..939f02bf78 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-59830.json +++ b/advisories/BREW-mailcatcher-CVE-2025-59830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-59830", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-625h-95r8-8xpm", "CVE-2025-59830" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "2.2.18", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61770.json b/advisories/BREW-mailcatcher-CVE-2025-61770.json index 88293d25ce..a37bb28022 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61770.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61770.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61770", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-p543-xpfm-54cp", "CVE-2025-61770" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.19", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61771.json b/advisories/BREW-mailcatcher-CVE-2025-61771.json index c03cf1d6ea..b4888ea8b1 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61771.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61771.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61771", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-w9pc-fmgc-vxvw", "CVE-2025-61771" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.19", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61772.json b/advisories/BREW-mailcatcher-CVE-2025-61772.json index e2ef26c575..ece0f159cc 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61772.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61772.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61772", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-wpv5-97wm-hp9c", "CVE-2025-61772" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.19", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61780.json b/advisories/BREW-mailcatcher-CVE-2025-61780.json index bd3ad19d79..ed7cd568e4 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61780.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61780.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61780", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-r657-rxjc-j557", "CVE-2025-61780" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.20", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.3", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61919.json b/advisories/BREW-mailcatcher-CVE-2025-61919.json index 26546bca21..af6d090b78 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61919.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61919.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61919", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-6xw4-3v39-52mm", "CVE-2025-61919" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.20", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.3", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61921.json b/advisories/BREW-mailcatcher-CVE-2025-61921.json index 553cff25d8..28a6a0a2d4 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61921.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61921.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61921", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-mr3q-g2mv-mr4q", "CVE-2025-61921" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "4.2.0", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-22860.json b/advisories/BREW-mailcatcher-CVE-2026-22860.json index 09f38e430a..df3fa54146 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-22860.json +++ b/advisories/BREW-mailcatcher-CVE-2026-22860.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-22860", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-mxw3-3hh2-x2mh", "CVE-2026-22860" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.22", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.5", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-25500.json b/advisories/BREW-mailcatcher-CVE-2026-25500.json index 1d4e3e9df1..de7b6ef3cb 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-25500.json +++ b/advisories/BREW-mailcatcher-CVE-2026-25500.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-25500", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-whrj-4476-wvmp", "CVE-2026-25500" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.22", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.5", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-26961.json b/advisories/BREW-mailcatcher-CVE-2026-26961.json index c8657ca95b..ebfe45cd4a 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-26961.json +++ b/advisories/BREW-mailcatcher-CVE-2026-26961.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-26961", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-vgpv-f759-9wx3", "CVE-2026-26961" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34230.json b/advisories/BREW-mailcatcher-CVE-2026-34230.json index c870c42de3..0527d5f226 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34230.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34230", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-v569-hp3g-36wr", "CVE-2026-34230" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34763.json b/advisories/BREW-mailcatcher-CVE-2026-34763.json index a2b19080a3..50b22e145e 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34763.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34763.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34763", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-7mqq-6cf9-v2qp", "CVE-2026-34763" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34785.json b/advisories/BREW-mailcatcher-CVE-2026-34785.json index 3533b1b9df..45aab98b0f 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34785.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34785.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34785", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-h2jq-g4cq-5ppq", "CVE-2026-34785" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34786.json b/advisories/BREW-mailcatcher-CVE-2026-34786.json index 76d33ecc41..5769ea022d 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34786.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34786.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34786", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-q4qf-9j86-f5mh", "CVE-2026-34786" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34826.json b/advisories/BREW-mailcatcher-CVE-2026-34826.json index 496f15a266..799d17a2b3 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34826.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34826.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34826", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-x8cg-fq8g-mxfx", "CVE-2026-34826" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34829.json b/advisories/BREW-mailcatcher-CVE-2026-34829.json index 2a2682354a..1d9317b9c9 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34829.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34829", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-8vqr-qjwx-82mw", "CVE-2026-34829" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34830.json b/advisories/BREW-mailcatcher-CVE-2026-34830.json index 5da5e665b7..6474a8a348 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34830.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34830", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-qv7j-4883-hwh7", "CVE-2026-34830" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34831.json b/advisories/BREW-mailcatcher-CVE-2026-34831.json index 7bb4a5556d..56de5c5a2c 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34831.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34831.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34831", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-q2ww-5357-x388", "CVE-2026-34831" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-42245.json b/advisories/BREW-mailcatcher-CVE-2026-42245.json index f24b408a7d..986c9e0d03 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-42245.json +++ b/advisories/BREW-mailcatcher-CVE-2026-42245.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-42245", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-q2mw-fvj9-vvcw", "CVE-2026-42245" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.24", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-42246.json b/advisories/BREW-mailcatcher-CVE-2026-42246.json index 2abff3341b..e0cd53ab9b 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-42246.json +++ b/advisories/BREW-mailcatcher-CVE-2026-42246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-42246", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-vcgp-9326-pqcp", "CVE-2026-42246" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.24", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-42256.json b/advisories/BREW-mailcatcher-CVE-2026-42256.json index be72241217..f8720cd177 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-42256.json +++ b/advisories/BREW-mailcatcher-CVE-2026-42256.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-42256", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-87pf-fpwv-p7m7", "CVE-2026-42256" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.24", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-42257.json b/advisories/BREW-mailcatcher-CVE-2026-42257.json index af36cb0213..2196b649b0 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-42257.json +++ b/advisories/BREW-mailcatcher-CVE-2026-42257.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-42257", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-hm49-wcqc-g2xg", "CVE-2026-42257" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.24", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-42258.json b/advisories/BREW-mailcatcher-CVE-2026-42258.json index ca52d6ee4e..d7ab297468 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-42258.json +++ b/advisories/BREW-mailcatcher-CVE-2026-42258.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-42258", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-75xq-5h9v-w6px", "CVE-2026-42258" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.24", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-47240.json b/advisories/BREW-mailcatcher-CVE-2026-47240.json index 8227b132ee..83d4eb211c 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-47240.json +++ b/advisories/BREW-mailcatcher-CVE-2026-47240.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-47240", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-8p34-64r3-mwg8", "CVE-2026-47240" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.5.15", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4.1", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-47241.json b/advisories/BREW-mailcatcher-CVE-2026-47241.json index 8cd84084da..2cef2cd8df 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-47241.json +++ b/advisories/BREW-mailcatcher-CVE-2026-47241.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-47241", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-c4fp-cxrr-mj66", "CVE-2026-47241" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.5.15", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4.1", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-47242.json b/advisories/BREW-mailcatcher-CVE-2026-47242.json index 85416ec2dc..08e9e1df98 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-47242.json +++ b/advisories/BREW-mailcatcher-CVE-2026-47242.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-47242", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-46q3-7gv7-qmgg", "CVE-2026-47242" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.5.15", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4.1", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-54463.json b/advisories/BREW-mailcatcher-CVE-2026-54463.json index 1e73556fe1..dc3742b2be 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-54463.json +++ b/advisories/BREW-mailcatcher-CVE-2026-54463.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-54463", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-17T17:29:14Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-ghhp-3qvg-889p", "CVE-2026-54463" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.8.1", "resource": "websocket-driver", - "resource_purl": "pkg:gem/websocket-driver@0.7.6" + "resource_purl": "pkg:gem/websocket-driver@0.8.2" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "websocket-driver", - "subject_version": "0.7.6", - "key": "pkg:gem/websocket-driver@0.7.6", + "subject_version": "0.8.2", + "key": "pkg:gem/websocket-driver@0.8.2", "resource": "websocket-driver" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-54464.json b/advisories/BREW-mailcatcher-CVE-2026-54464.json index 660f531caa..5cfb29a265 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-54464.json +++ b/advisories/BREW-mailcatcher-CVE-2026-54464.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-54464", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-17T17:29:14Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-33ph-fccm-39pj", "CVE-2026-54464" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.8.1", "resource": "websocket-driver", - "resource_purl": "pkg:gem/websocket-driver@0.7.6" + "resource_purl": "pkg:gem/websocket-driver@0.8.2" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "websocket-driver", - "subject_version": "0.7.6", - "key": "pkg:gem/websocket-driver@0.7.6", + "subject_version": "0.8.2", + "key": "pkg:gem/websocket-driver@0.8.2", "resource": "websocket-driver" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-54465.json b/advisories/BREW-mailcatcher-CVE-2026-54465.json index ee15ec9a4d..ed962ef3a0 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-54465.json +++ b/advisories/BREW-mailcatcher-CVE-2026-54465.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-54465", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-17T17:29:14Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-8j3g-f24p-4mpw", "CVE-2026-54465" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.8.1", "resource": "websocket-driver", - "resource_purl": "pkg:gem/websocket-driver@0.7.6" + "resource_purl": "pkg:gem/websocket-driver@0.8.2" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "websocket-driver", - "subject_version": "0.7.6", - "key": "pkg:gem/websocket-driver@0.7.6", + "subject_version": "0.8.2", + "key": "pkg:gem/websocket-driver@0.8.2", "resource": "websocket-driver" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-54619.json b/advisories/BREW-mailcatcher-CVE-2026-54619.json index caba4b46b3..3f02ad2c6c 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-54619.json +++ b/advisories/BREW-mailcatcher-CVE-2026-54619.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-54619", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-28hh-pr2h-2w89", "CVE-2026-54619" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "2.9.5", "resource": "sqlite", - "resource_purl": "pkg:gem/sqlite3@1.7.3" + "resource_purl": "pkg:gem/sqlite3@2.9.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sqlite3", - "subject_version": "1.7.3", - "key": "pkg:gem/sqlite3@1.7.3", + "subject_version": "2.9.6", + "key": "pkg:gem/sqlite3@2.9.6", "resource": "sqlite" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-61666.json b/advisories/BREW-mailcatcher-CVE-2026-61666.json index 140df28d88..1604f7e0d2 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-61666.json +++ b/advisories/BREW-mailcatcher-CVE-2026-61666.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-61666", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-2x63-gw47-w4mm", "CVE-2026-61666" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.8.2", "resource": "websocket-driver", - "resource_purl": "pkg:gem/websocket-driver@0.7.6" + "resource_purl": "pkg:gem/websocket-driver@0.8.2" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "websocket-driver", - "subject_version": "0.7.6", - "key": "pkg:gem/websocket-driver@0.7.6", + "subject_version": "0.8.2", + "key": "pkg:gem/websocket-driver@0.8.2", "resource": "websocket-driver" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-63435.json b/advisories/BREW-mailcatcher-CVE-2026-63435.json index 10024426f6..4b99a4f870 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-63435.json +++ b/advisories/BREW-mailcatcher-CVE-2026-63435.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-63435", "published": "2026-09-03T09:29:48Z", - "modified": "2026-09-03T09:29:48Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-mvxr-6m87-mv2q", "CVE-2026-63435" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "2.9.1", "resource": "mail", - "resource_purl": "pkg:gem/mail@2.8.1" + "resource_purl": "pkg:gem/mail@2.9.1" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "mail", - "subject_version": "2.8.1", - "key": "pkg:gem/mail@2.8.1", + "subject_version": "2.9.1", + "key": "pkg:gem/mail@2.9.1", "resource": "mail" } ] diff --git a/advisories/BREW-mailcatcher-GHSA-mgvv-5mxp-xq67.json b/advisories/BREW-mailcatcher-GHSA-mgvv-5mxp-xq67.json index 59c3d7ff46..0bdf6f1f4c 100644 --- a/advisories/BREW-mailcatcher-GHSA-mgvv-5mxp-xq67.json +++ b/advisories/BREW-mailcatcher-GHSA-mgvv-5mxp-xq67.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-GHSA-mgvv-5mxp-xq67", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-mgvv-5mxp-xq67" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.1", "resource": "sqlite", - "resource_purl": "pkg:gem/sqlite3@1.7.3" + "resource_purl": "pkg:gem/sqlite3@2.9.6" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sqlite3", - "subject_version": "1.7.3", - "key": "pkg:gem/sqlite3@1.7.3", + "subject_version": "2.9.6", + "key": "pkg:gem/sqlite3@2.9.6", "resource": "sqlite" } ] diff --git a/advisories/BREW-mentat-CVE-2026-76221.json b/advisories/BREW-mentat-CVE-2026-76221.json index ee84f7472c..d378307fa3 100644 --- a/advisories/BREW-mentat-CVE-2026-76221.json +++ b/advisories/BREW-mentat-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mentat-CVE-2026-76221", "published": "2026-08-20T09:16:35Z", - "modified": "2026-08-20T09:16:35Z", + "modified": "2026-09-04T09:30:36Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mentat-CVE-2026-76222.json b/advisories/BREW-mentat-CVE-2026-76222.json index 9b1ca0ba2e..bf5d8b7ce4 100644 --- a/advisories/BREW-mentat-CVE-2026-76222.json +++ b/advisories/BREW-mentat-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mentat-CVE-2026-76222", "published": "2026-08-20T09:16:35Z", - "modified": "2026-08-20T09:16:35Z", + "modified": "2026-09-04T09:30:36Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mentat-CVE-2026-78675.json b/advisories/BREW-mentat-CVE-2026-78675.json new file mode 100644 index 0000000000..f371430dd4 --- /dev/null +++ b/advisories/BREW-mentat-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mentat-CVE-2026-78675", + "published": "2026-09-04T09:30:36Z", + "modified": "2026-09-04T09:30:36Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mentat", + "purl": "pkg:brew/mentat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.37" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-mentat-CVE-2026-78676.json b/advisories/BREW-mentat-CVE-2026-78676.json new file mode 100644 index 0000000000..f573662f4b --- /dev/null +++ b/advisories/BREW-mentat-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mentat-CVE-2026-78676", + "published": "2026-09-04T09:30:36Z", + "modified": "2026-09-04T09:30:36Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mentat", + "purl": "pkg:brew/mentat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.37" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-mentat-CVE-2026-78677.json b/advisories/BREW-mentat-CVE-2026-78677.json new file mode 100644 index 0000000000..ca64c3dba4 --- /dev/null +++ b/advisories/BREW-mentat-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mentat-CVE-2026-78677", + "published": "2026-09-04T09:30:36Z", + "modified": "2026-09-04T09:30:36Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mentat", + "purl": "pkg:brew/mentat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.37" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-mentat-CVE-2026-78678.json b/advisories/BREW-mentat-CVE-2026-78678.json new file mode 100644 index 0000000000..d8a8ad1852 --- /dev/null +++ b/advisories/BREW-mentat-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mentat-CVE-2026-78678", + "published": "2026-09-04T09:30:36Z", + "modified": "2026-09-04T09:30:36Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mentat", + "purl": "pkg:brew/mentat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.37" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-mentat-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-mentat-GHSA-hmq2-w58f-27jc.json index 24a02986cd..f8661a5c34 100644 --- a/advisories/BREW-mentat-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-mentat-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mentat-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:13:16Z", - "modified": "2026-08-29T09:17:15Z", + "modified": "2026-09-04T09:30:36Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mentat-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-mentat-GHSA-jm78-9fvv-mhgr.json index 0d2a9e260b..5d87886a30 100644 --- a/advisories/BREW-mentat-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-mentat-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mentat-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:13:16Z", - "modified": "2026-08-29T09:17:15Z", + "modified": "2026-09-04T09:30:36Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mistral-vibe-CVE-2026-76221.json b/advisories/BREW-mistral-vibe-CVE-2026-76221.json index 470b9887b0..93157f96c0 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-76221.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-76221", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-23T21:08:24Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mistral-vibe-CVE-2026-76222.json b/advisories/BREW-mistral-vibe-CVE-2026-76222.json index d9633f340b..49716da186 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-76222.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-76222", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-23T21:08:24Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mistral-vibe-CVE-2026-78675.json b/advisories/BREW-mistral-vibe-CVE-2026-78675.json new file mode 100644 index 0000000000..dea0463813 --- /dev/null +++ b/advisories/BREW-mistral-vibe-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mistral-vibe-CVE-2026-78675", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mistral-vibe", + "purl": "pkg:brew/mistral-vibe" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-mistral-vibe-CVE-2026-78676.json b/advisories/BREW-mistral-vibe-CVE-2026-78676.json new file mode 100644 index 0000000000..a049d8b013 --- /dev/null +++ b/advisories/BREW-mistral-vibe-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mistral-vibe-CVE-2026-78676", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mistral-vibe", + "purl": "pkg:brew/mistral-vibe" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-mistral-vibe-CVE-2026-78677.json b/advisories/BREW-mistral-vibe-CVE-2026-78677.json new file mode 100644 index 0000000000..c2a6753d32 --- /dev/null +++ b/advisories/BREW-mistral-vibe-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mistral-vibe-CVE-2026-78677", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mistral-vibe", + "purl": "pkg:brew/mistral-vibe" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-mistral-vibe-CVE-2026-78678.json b/advisories/BREW-mistral-vibe-CVE-2026-78678.json new file mode 100644 index 0000000000..c447215469 --- /dev/null +++ b/advisories/BREW-mistral-vibe-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mistral-vibe-CVE-2026-78678", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mistral-vibe", + "purl": "pkg:brew/mistral-vibe" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-mistral-vibe-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-mistral-vibe-GHSA-hmq2-w58f-27jc.json index 4e317e1ac5..4e5f6847a0 100644 --- a/advisories/BREW-mistral-vibe-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-mistral-vibe-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-29T09:19:43Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr.json index fbce2f7970..2d6f728e39 100644 --- a/advisories/BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-29T09:19:43Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mk-CVE-2026-76221.json b/advisories/BREW-mk-CVE-2026-76221.json index 965a58b75f..e6a0b9a15c 100644 --- a/advisories/BREW-mk-CVE-2026-76221.json +++ b/advisories/BREW-mk-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mk-CVE-2026-76221", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-20T09:17:34Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mk-CVE-2026-76222.json b/advisories/BREW-mk-CVE-2026-76222.json index 0335418d5c..d69074e49b 100644 --- a/advisories/BREW-mk-CVE-2026-76222.json +++ b/advisories/BREW-mk-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mk-CVE-2026-76222", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-20T09:17:34Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mk-CVE-2026-78675.json b/advisories/BREW-mk-CVE-2026-78675.json new file mode 100644 index 0000000000..75e6a964c7 --- /dev/null +++ b/advisories/BREW-mk-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mk-CVE-2026-78675", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mk", + "purl": "pkg:brew/mk" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-mk-CVE-2026-78676.json b/advisories/BREW-mk-CVE-2026-78676.json new file mode 100644 index 0000000000..4f79328c2f --- /dev/null +++ b/advisories/BREW-mk-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mk-CVE-2026-78676", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mk", + "purl": "pkg:brew/mk" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-mk-CVE-2026-78677.json b/advisories/BREW-mk-CVE-2026-78677.json new file mode 100644 index 0000000000..50da977430 --- /dev/null +++ b/advisories/BREW-mk-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mk-CVE-2026-78677", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mk", + "purl": "pkg:brew/mk" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-mk-CVE-2026-78678.json b/advisories/BREW-mk-CVE-2026-78678.json new file mode 100644 index 0000000000..8b94408b7d --- /dev/null +++ b/advisories/BREW-mk-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mk-CVE-2026-78678", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mk", + "purl": "pkg:brew/mk" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-mk-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-mk-GHSA-hmq2-w58f-27jc.json index 6a5c517bd7..3fd2623016 100644 --- a/advisories/BREW-mk-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-mk-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mk-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-29T09:19:43Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mk-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-mk-GHSA-jm78-9fvv-mhgr.json index 11a7582103..489971b92a 100644 --- a/advisories/BREW-mk-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-mk-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mk-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-29T09:19:43Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-material-CVE-2026-73295.json b/advisories/BREW-mkdocs-material-CVE-2026-73295.json new file mode 100644 index 0000000000..b55c7fefba --- /dev/null +++ b/advisories/BREW-mkdocs-material-CVE-2026-73295.json @@ -0,0 +1,100 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mkdocs-material-CVE-2026-73295", + "published": "2026-09-04T09:32:39Z", + "modified": "2026-09-04T09:32:39Z", + "upstream": [ + "GHSA-xvg9-69gf-fjrf", + "CVE-2026-73295" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mkdocs-material", + "purl": "pkg:brew/mkdocs-material" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.7.7" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "9.7.7" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "mkdocs-material", + "subject_version": "9.7.7", + "key": "pkg:pypi/mkdocs-material@9.7.7" + }, + { + "strategy": "distro", + "ecosystem": "Debian", + "name": "mkdocs-material", + "key": "Debian/mkdocs-material" + }, + { + "strategy": "distro", + "ecosystem": "PyPI", + "name": "mkdocs-material", + "subject_version": "9.7.7", + "key": "upstream:pkg:pypi/mkdocs-material@9.7.7" + }, + { + "strategy": "distro", + "ecosystem": "Ubuntu", + "name": "mkdocs-material", + "key": "Ubuntu/mkdocs-material" + } + ] + }, + "summary": "Material for MkDocs: DOM XSS in search suggestions via query parameter", + "details": "### Impact\n\nMaterial for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional `search.suggest` feature. A crafted `q` URL parameter could execute JavaScript in the documentation site's origin after user interaction.\n\n### Patches\n\nThe issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later.\n\n### Workarounds\n\nSites unable to upgrade should disable the `search.suggest` feature.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73295" + }, + { + "type": "WEB", + "url": "https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25" + }, + { + "type": "PACKAGE", + "url": "https://github.com/squidfunk/mkdocs-material" + }, + { + "type": "WEB", + "url": "https://github.com/squidfunk/mkdocs-material/releases/tag/9.7.7" + } + ] +} diff --git a/advisories/BREW-mycli-CVE-2021-32839.json b/advisories/BREW-mycli-CVE-2021-32839.json index fa4f97f613..8451a14dce 100644 --- a/advisories/BREW-mycli-CVE-2021-32839.json +++ b/advisories/BREW-mycli-CVE-2021-32839.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2021-32839", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-p5w8-wqhj-9hhf", "CVE-2021-32839", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.4.2", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2023-30608.json b/advisories/BREW-mycli-CVE-2023-30608.json index 50d6771ddc..fc0d57dfae 100644 --- a/advisories/BREW-mycli-CVE-2023-30608.json +++ b/advisories/BREW-mycli-CVE-2023-30608.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2023-30608", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-rrm6-wvj7-cwh2", "CVE-2023-30608", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.4.4", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2023-44690.json b/advisories/BREW-mycli-CVE-2023-44690.json index a8ed820ca6..c299d5394f 100644 --- a/advisories/BREW-mycli-CVE-2023-44690.json +++ b/advisories/BREW-mycli-CVE-2023-44690.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2023-44690", "published": "2026-08-13T17:16:44Z", - "modified": "2026-09-02T09:27:36Z", + "modified": "2026-09-04T09:35:11Z", "upstream": [ "GHSA-v9vj-9pxv-mr2w", "CVE-2023-44690", @@ -40,15 +40,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mycli", - "subject_version": "2.18.5", - "key": "pkg:pypi/mycli@2.18.5" + "subject_version": "2.19.0", + "key": "pkg:pypi/mycli@2.19.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "mycli", - "subject_version": "2.18.5", - "key": "pkg:pypi/mycli@2.18.5" + "subject_version": "2.19.0", + "key": "pkg:pypi/mycli@2.19.0" }, { "strategy": "distro", @@ -60,8 +60,8 @@ "strategy": "distro", "ecosystem": "PyPI", "name": "mycli", - "subject_version": "2.18.5", - "key": "upstream:pkg:pypi/mycli@2.18.5" + "subject_version": "2.19.0", + "key": "upstream:pkg:pypi/mycli@2.19.0" }, { "strategy": "distro", diff --git a/advisories/BREW-mycli-CVE-2024-4340.json b/advisories/BREW-mycli-CVE-2024-4340.json index 5998f3fd03..d7d7d0caa9 100644 --- a/advisories/BREW-mycli-CVE-2024-4340.json +++ b/advisories/BREW-mycli-CVE-2024-4340.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2024-4340", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-09-04T09:35:11Z", "upstream": [ "GHSA-2m57-hf25-phgg", "CVE-2024-4340", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.5.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2026-31236.json b/advisories/BREW-mycli-CVE-2026-31236.json index 0921afa72e..e3572d1a4f 100644 --- a/advisories/BREW-mycli-CVE-2026-31236.json +++ b/advisories/BREW-mycli-CVE-2026-31236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-31236", "published": "2026-08-13T17:16:44Z", - "modified": "2026-09-03T09:36:22Z", + "modified": "2026-09-04T09:35:11Z", "upstream": [ "GHSA-g76p-4vg5-f4qh", "CVE-2026-31236", @@ -32,7 +32,7 @@ "fix": "bump", "range_state": "fixed", "resource": "llm", - "resource_purl": "pkg:pypi/llm@0.33" + "resource_purl": "pkg:pypi/llm@0.34" } } ], @@ -45,16 +45,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "llm", - "subject_version": "0.33", - "key": "pkg:pypi/llm@0.33", + "subject_version": "0.34", + "key": "pkg:pypi/llm@0.34", "resource": "llm" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "llm", - "subject_version": "0.33", - "key": "pkg:pypi/llm@0.33", + "subject_version": "0.34", + "key": "pkg:pypi/llm@0.34", "resource": "llm" } ] diff --git a/advisories/BREW-mycli-CVE-2026-54284.json b/advisories/BREW-mycli-CVE-2026-54284.json index ea12221e43..d2c97da469 100644 --- a/advisories/BREW-mycli-CVE-2026-54284.json +++ b/advisories/BREW-mycli-CVE-2026-54284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-54284", "published": "2026-08-18T09:19:28Z", - "modified": "2026-08-20T09:21:59Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-pwgv-4x5q-6m9f", "CVE-2026-54284", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.19.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.6.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -43,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2026-59893.json b/advisories/BREW-mycli-CVE-2026-59893.json index c7363dd69a..2929be0617 100644 --- a/advisories/BREW-mycli-CVE-2026-59893.json +++ b/advisories/BREW-mycli-CVE-2026-59893.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-59893", "published": "2026-08-18T09:19:28Z", - "modified": "2026-08-20T09:21:59Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-prg7-hcfm-mfcr", "CVE-2026-59893", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.19.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.6.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -43,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2026-59894.json b/advisories/BREW-mycli-CVE-2026-59894.json index 572e5257e3..dcf764658e 100644 --- a/advisories/BREW-mycli-CVE-2026-59894.json +++ b/advisories/BREW-mycli-CVE-2026-59894.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-59894", "published": "2026-08-17T17:34:03Z", - "modified": "2026-08-20T09:21:59Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-3496-9g83-7v6x", "CVE-2026-59894", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.19.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.6.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -43,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2026-71491.json b/advisories/BREW-mycli-CVE-2026-71491.json index b7bec73cb4..ff07c78789 100644 --- a/advisories/BREW-mycli-CVE-2026-71491.json +++ b/advisories/BREW-mycli-CVE-2026-71491.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-71491", "published": "2026-08-17T17:34:03Z", - "modified": "2026-08-20T09:21:59Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-f2ff-p2ww-7p4p", "CVE-2026-71491", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.19.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.6.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -43,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2026-7246.json b/advisories/BREW-mycli-CVE-2026-7246.json index 941813b0c0..d8badfb043 100644 --- a/advisories/BREW-mycli-CVE-2026-7246.json +++ b/advisories/BREW-mycli-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-7246", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-09-04T09:35:11Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.3.3" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.3.3", - "key": "pkg:pypi/click@8.3.3", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-mycli-CVE-2026-84305.json b/advisories/BREW-mycli-CVE-2026-84305.json index c3876c3b69..e8eeb5ce81 100644 --- a/advisories/BREW-mycli-CVE-2026-84305.json +++ b/advisories/BREW-mycli-CVE-2026-84305.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-84305", "published": "2026-09-02T09:27:36Z", - "modified": "2026-09-02T09:27:36Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-cfqr-cjx5-5jcm", "CVE-2026-84305" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.19.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.6.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-GHSA-27jp-wm6q-gp25.json b/advisories/BREW-mycli-GHSA-27jp-wm6q-gp25.json index fd5169e3f9..c3996a7f9b 100644 --- a/advisories/BREW-mycli-GHSA-27jp-wm6q-gp25.json +++ b/advisories/BREW-mycli-GHSA-27jp-wm6q-gp25.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-GHSA-27jp-wm6q-gp25", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-09-04T09:35:11Z", "upstream": [ "GHSA-27jp-wm6q-gp25" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.5.4", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-n8n-mcp-CVE-2026-39974.json b/advisories/BREW-n8n-mcp-CVE-2026-39974.json index 45ba4737a1..50c159785e 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-39974.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-39974.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-39974", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-4ggg-h7ph-26qr", "CVE-2026-39974" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-41495.json b/advisories/BREW-n8n-mcp-CVE-2026-41495.json index 96c3e52135..415a7fb46f 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-41495.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-41495.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-41495", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-pfm2-2mhg-8wpx", "CVE-2026-41495" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-42282.json b/advisories/BREW-n8n-mcp-CVE-2026-42282.json index 38603b8767..cbf147fcaf 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-42282.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-42282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-42282", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-wg4g-395p-mqv3", "CVE-2026-42282" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-42449.json b/advisories/BREW-n8n-mcp-CVE-2026-42449.json index 500e26213e..2173340f23 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-42449.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-42449.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-42449", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-56c3-vfp2-5qqj", "CVE-2026-42449" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-44694.json b/advisories/BREW-n8n-mcp-CVE-2026-44694.json index 58155caf09..d336809891 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-44694.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-44694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-44694", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-cmrh-wvq6-wm9r", "CVE-2026-44694" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-45582.json b/advisories/BREW-n8n-mcp-CVE-2026-45582.json index 9e633fabcf..c9abbecb75 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-45582.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-45582.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-45582", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-f3rg-xqjj-cj9w", "CVE-2026-45582" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-45707.json b/advisories/BREW-n8n-mcp-CVE-2026-45707.json index 218c9f1332..826ff9fc7f 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-45707.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-45707.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-45707", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-jxx9-px88-pj69", "CVE-2026-45707" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-54052.json b/advisories/BREW-n8n-mcp-CVE-2026-54052.json index feea10e110..f6d1e4abf0 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-54052.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-54052.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-54052", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-j6r7-6fhx-77wx", "CVE-2026-54052" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-55608.json b/advisories/BREW-n8n-mcp-CVE-2026-55608.json index 04d352aeb0..0386ba82c6 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-55608.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-55608.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-55608", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-2cf7-hpwf-47h9", "CVE-2026-55608" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json b/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json index bc9fbc0acc..b067f7881d 100644 --- a/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json +++ b/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-GHSA-75hx-xj24-mqrw", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-75hx-xj24-mqrw" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json b/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json index 96921dcaf9..6e60d7d5ca 100644 --- a/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json +++ b/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-8g7g-hmwm-6rv2" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-nbdime-CVE-2026-76221.json b/advisories/BREW-nbdime-CVE-2026-76221.json index d4b0e25294..7f2a0ea8fa 100644 --- a/advisories/BREW-nbdime-CVE-2026-76221.json +++ b/advisories/BREW-nbdime-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-nbdime-CVE-2026-76221", "published": "2026-08-20T09:22:15Z", - "modified": "2026-08-20T09:22:15Z", + "modified": "2026-09-04T09:36:43Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-nbdime-CVE-2026-76222.json b/advisories/BREW-nbdime-CVE-2026-76222.json index ff0683d813..f1ff8fc54f 100644 --- a/advisories/BREW-nbdime-CVE-2026-76222.json +++ b/advisories/BREW-nbdime-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-nbdime-CVE-2026-76222", "published": "2026-08-20T09:22:15Z", - "modified": "2026-08-20T09:22:15Z", + "modified": "2026-09-04T09:36:43Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-nbdime-CVE-2026-78675.json b/advisories/BREW-nbdime-CVE-2026-78675.json new file mode 100644 index 0000000000..5fda5a6d81 --- /dev/null +++ b/advisories/BREW-nbdime-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-nbdime-CVE-2026-78675", + "published": "2026-09-04T09:36:43Z", + "modified": "2026-09-04T09:36:43Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "nbdime", + "purl": "pkg:brew/nbdime" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-nbdime-CVE-2026-78676.json b/advisories/BREW-nbdime-CVE-2026-78676.json new file mode 100644 index 0000000000..2bcc58139c --- /dev/null +++ b/advisories/BREW-nbdime-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-nbdime-CVE-2026-78676", + "published": "2026-09-04T09:36:43Z", + "modified": "2026-09-04T09:36:43Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "nbdime", + "purl": "pkg:brew/nbdime" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-nbdime-CVE-2026-78677.json b/advisories/BREW-nbdime-CVE-2026-78677.json new file mode 100644 index 0000000000..643fa4b3d9 --- /dev/null +++ b/advisories/BREW-nbdime-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-nbdime-CVE-2026-78677", + "published": "2026-09-04T09:36:43Z", + "modified": "2026-09-04T09:36:43Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "nbdime", + "purl": "pkg:brew/nbdime" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-nbdime-CVE-2026-78678.json b/advisories/BREW-nbdime-CVE-2026-78678.json new file mode 100644 index 0000000000..6664fd0e7b --- /dev/null +++ b/advisories/BREW-nbdime-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-nbdime-CVE-2026-78678", + "published": "2026-09-04T09:36:43Z", + "modified": "2026-09-04T09:36:43Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "nbdime", + "purl": "pkg:brew/nbdime" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-nbdime-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-nbdime-GHSA-hmq2-w58f-27jc.json index 195f8dbbfa..77bf4a1aed 100644 --- a/advisories/BREW-nbdime-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-nbdime-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-nbdime-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:17:04Z", - "modified": "2026-08-29T09:22:33Z", + "modified": "2026-09-04T09:36:43Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-nbdime-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-nbdime-GHSA-jm78-9fvv-mhgr.json index 76c0d05306..b68ec87808 100644 --- a/advisories/BREW-nbdime-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-nbdime-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-nbdime-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:17:04Z", - "modified": "2026-08-29T09:22:33Z", + "modified": "2026-09-04T09:36:43Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-nx-CVE-2026-54753.json b/advisories/BREW-nx-CVE-2026-54753.json index 8c0c0d46db..e718ce6c92 100644 --- a/advisories/BREW-nx-CVE-2026-54753.json +++ b/advisories/BREW-nx-CVE-2026-54753.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-nx-CVE-2026-54753", "published": "2026-08-13T17:19:21Z", - "modified": "2026-09-02T09:30:17Z", + "modified": "2026-09-04T09:39:03Z", "upstream": [ "GHSA-g2r8-wvmj-jf5w", "CVE-2026-54753" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "nx", - "subject_version": "23.1.3", - "key": "pkg:npm/nx@23.1.3" + "subject_version": "23.2.0", + "key": "pkg:npm/nx@23.2.0" } ] }, diff --git a/advisories/BREW-nx-CVE-2026-71476.json b/advisories/BREW-nx-CVE-2026-71476.json index 98202dcd38..f1b461894d 100644 --- a/advisories/BREW-nx-CVE-2026-71476.json +++ b/advisories/BREW-nx-CVE-2026-71476.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-nx-CVE-2026-71476", "published": "2026-08-13T17:19:21Z", - "modified": "2026-09-02T09:30:17Z", + "modified": "2026-09-04T09:39:03Z", "upstream": [ "GHSA-vp3h-ghgh-jr7g", "CVE-2026-71476" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "nx", - "subject_version": "23.1.3", - "key": "pkg:npm/nx@23.1.3" + "subject_version": "23.2.0", + "key": "pkg:npm/nx@23.2.0" } ] }, diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-76221.json b/advisories/BREW-opentimestamps-client-CVE-2026-76221.json index 2d29f225eb..08f725a719 100644 --- a/advisories/BREW-opentimestamps-client-CVE-2026-76221.json +++ b/advisories/BREW-opentimestamps-client-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-opentimestamps-client-CVE-2026-76221", "published": "2026-08-20T09:30:00Z", - "modified": "2026-08-20T09:30:00Z", + "modified": "2026-09-04T09:43:41Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-76222.json b/advisories/BREW-opentimestamps-client-CVE-2026-76222.json index 6a73eb30e0..597eb97d84 100644 --- a/advisories/BREW-opentimestamps-client-CVE-2026-76222.json +++ b/advisories/BREW-opentimestamps-client-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-opentimestamps-client-CVE-2026-76222", "published": "2026-08-20T09:30:00Z", - "modified": "2026-08-20T09:30:00Z", + "modified": "2026-09-04T09:43:41Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-78675.json b/advisories/BREW-opentimestamps-client-CVE-2026-78675.json new file mode 100644 index 0000000000..d09b594bbd --- /dev/null +++ b/advisories/BREW-opentimestamps-client-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-opentimestamps-client-CVE-2026-78675", + "published": "2026-09-04T09:43:41Z", + "modified": "2026-09-04T09:43:41Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "opentimestamps-client", + "purl": "pkg:brew/opentimestamps-client" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-78676.json b/advisories/BREW-opentimestamps-client-CVE-2026-78676.json new file mode 100644 index 0000000000..9d9e777d69 --- /dev/null +++ b/advisories/BREW-opentimestamps-client-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-opentimestamps-client-CVE-2026-78676", + "published": "2026-09-04T09:43:41Z", + "modified": "2026-09-04T09:43:41Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "opentimestamps-client", + "purl": "pkg:brew/opentimestamps-client" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-78677.json b/advisories/BREW-opentimestamps-client-CVE-2026-78677.json new file mode 100644 index 0000000000..b6a227abe1 --- /dev/null +++ b/advisories/BREW-opentimestamps-client-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-opentimestamps-client-CVE-2026-78677", + "published": "2026-09-04T09:43:41Z", + "modified": "2026-09-04T09:43:41Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "opentimestamps-client", + "purl": "pkg:brew/opentimestamps-client" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-78678.json b/advisories/BREW-opentimestamps-client-CVE-2026-78678.json new file mode 100644 index 0000000000..74cb9d0f9d --- /dev/null +++ b/advisories/BREW-opentimestamps-client-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-opentimestamps-client-CVE-2026-78678", + "published": "2026-09-04T09:43:41Z", + "modified": "2026-09-04T09:43:41Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "opentimestamps-client", + "purl": "pkg:brew/opentimestamps-client" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-opentimestamps-client-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-opentimestamps-client-GHSA-hmq2-w58f-27jc.json index d567660ed0..2938f418cd 100644 --- a/advisories/BREW-opentimestamps-client-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-opentimestamps-client-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-opentimestamps-client-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:24:07Z", - "modified": "2026-08-29T09:29:27Z", + "modified": "2026-09-04T09:43:41Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-opentimestamps-client-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-opentimestamps-client-GHSA-jm78-9fvv-mhgr.json index 5fe8ed5192..ebe9a62e77 100644 --- a/advisories/BREW-opentimestamps-client-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-opentimestamps-client-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-opentimestamps-client-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:24:07Z", - "modified": "2026-08-29T09:29:27Z", + "modified": "2026-09-04T09:43:41Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-otterdog-CVE-2026-76221.json b/advisories/BREW-otterdog-CVE-2026-76221.json index bc4647b64e..ad1672b8b8 100644 --- a/advisories/BREW-otterdog-CVE-2026-76221.json +++ b/advisories/BREW-otterdog-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-otterdog-CVE-2026-76221", "published": "2026-08-20T09:30:09Z", - "modified": "2026-08-20T09:30:09Z", + "modified": "2026-09-04T09:44:25Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-otterdog-CVE-2026-76222.json b/advisories/BREW-otterdog-CVE-2026-76222.json index dec92aa9b6..160073a910 100644 --- a/advisories/BREW-otterdog-CVE-2026-76222.json +++ b/advisories/BREW-otterdog-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-otterdog-CVE-2026-76222", "published": "2026-08-20T09:30:09Z", - "modified": "2026-08-20T09:30:09Z", + "modified": "2026-09-04T09:44:25Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-otterdog-CVE-2026-78675.json b/advisories/BREW-otterdog-CVE-2026-78675.json new file mode 100644 index 0000000000..552ced3e75 --- /dev/null +++ b/advisories/BREW-otterdog-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-otterdog-CVE-2026-78675", + "published": "2026-09-04T09:44:25Z", + "modified": "2026-09-04T09:44:25Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "otterdog", + "purl": "pkg:brew/otterdog" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-otterdog-CVE-2026-78676.json b/advisories/BREW-otterdog-CVE-2026-78676.json new file mode 100644 index 0000000000..41dff1dcda --- /dev/null +++ b/advisories/BREW-otterdog-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-otterdog-CVE-2026-78676", + "published": "2026-09-04T09:44:25Z", + "modified": "2026-09-04T09:44:25Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "otterdog", + "purl": "pkg:brew/otterdog" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-otterdog-CVE-2026-78677.json b/advisories/BREW-otterdog-CVE-2026-78677.json new file mode 100644 index 0000000000..f5cdf86eb9 --- /dev/null +++ b/advisories/BREW-otterdog-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-otterdog-CVE-2026-78677", + "published": "2026-09-04T09:44:25Z", + "modified": "2026-09-04T09:44:25Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "otterdog", + "purl": "pkg:brew/otterdog" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-otterdog-CVE-2026-78678.json b/advisories/BREW-otterdog-CVE-2026-78678.json new file mode 100644 index 0000000000..b620c7d126 --- /dev/null +++ b/advisories/BREW-otterdog-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-otterdog-CVE-2026-78678", + "published": "2026-09-04T09:44:25Z", + "modified": "2026-09-04T09:44:25Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "otterdog", + "purl": "pkg:brew/otterdog" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-otterdog-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-otterdog-GHSA-hmq2-w58f-27jc.json index fee89e0409..4fc1afcea5 100644 --- a/advisories/BREW-otterdog-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-otterdog-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-otterdog-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-29T09:30:12Z", + "modified": "2026-09-04T09:44:25Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-otterdog-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-otterdog-GHSA-jm78-9fvv-mhgr.json index c3e8e8bfb0..f42006b8ad 100644 --- a/advisories/BREW-otterdog-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-otterdog-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-otterdog-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-29T09:30:12Z", + "modified": "2026-09-04T09:44:25Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-prowler-CVE-2015-5237.json b/advisories/BREW-prowler-CVE-2015-5237.json index 2a2e257a4f..7ebd130599 100644 --- a/advisories/BREW-prowler-CVE-2015-5237.json +++ b/advisories/BREW-prowler-CVE-2015-5237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2015-5237", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-jwvw-v7c5-m82h", "CVE-2015-5237", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.4.0", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@7.36.0" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-prowler-CVE-2016-6298.json b/advisories/BREW-prowler-CVE-2016-6298.json index 27f7e3f798..3933602186 100644 --- a/advisories/BREW-prowler-CVE-2016-6298.json +++ b/advisories/BREW-prowler-CVE-2016-6298.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2016-6298", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-wg33-x934-3ghh", "CVE-2016-6298", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.3.2", "resource": "jwcrypto", - "resource_purl": "pkg:pypi/jwcrypto@1.5.9" + "resource_purl": "pkg:pypi/jwcrypto@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" } ] diff --git a/advisories/BREW-prowler-CVE-2021-22570.json b/advisories/BREW-prowler-CVE-2021-22570.json index a231cbc548..8ea9281437 100644 --- a/advisories/BREW-prowler-CVE-2021-22570.json +++ b/advisories/BREW-prowler-CVE-2021-22570.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2021-22570", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "PYSEC-2022-48", "CVE-2021-22570", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15.0", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@7.36.0" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-prowler-CVE-2022-1941.json b/advisories/BREW-prowler-CVE-2022-1941.json index 4d0b4eb4c5..bd0aed5459 100644 --- a/advisories/BREW-prowler-CVE-2022-1941.json +++ b/advisories/BREW-prowler-CVE-2022-1941.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2022-1941", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-8gq9-2x98-w8hf", "CVE-2022-1941", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.21.6", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@7.36.0" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-prowler-CVE-2022-3102.json b/advisories/BREW-prowler-CVE-2022-3102.json index 9b1ad4615f..2a621bd464 100644 --- a/advisories/BREW-prowler-CVE-2022-3102.json +++ b/advisories/BREW-prowler-CVE-2022-3102.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2022-3102", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-gwp4-mcv4-w95j", "CVE-2022-3102", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.4", "resource": "jwcrypto", - "resource_purl": "pkg:pypi/jwcrypto@1.5.9" + "resource_purl": "pkg:pypi/jwcrypto@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" } ] diff --git a/advisories/BREW-prowler-CVE-2023-26145.json b/advisories/BREW-prowler-CVE-2023-26145.json index 0aba3272c1..ffe45e7f79 100644 --- a/advisories/BREW-prowler-CVE-2023-26145.json +++ b/advisories/BREW-prowler-CVE-2023-26145.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2023-26145", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-13T17:29:23Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-8mjr-6c96-39w8", "CVE-2023-26145", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.0.0", "resource": "pydash", - "resource_purl": "pkg:pypi/pydash@8.0.6" + "resource_purl": "pkg:pypi/pydash@8.1.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydash", - "subject_version": "8.0.6", - "key": "pkg:pypi/pydash@8.0.6", + "subject_version": "8.1.0", + "key": "pkg:pypi/pydash@8.1.0", "resource": "pydash" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pydash", - "subject_version": "8.0.6", - "key": "pkg:pypi/pydash@8.0.6", + "subject_version": "8.1.0", + "key": "pkg:pypi/pydash@8.1.0", "resource": "pydash" } ] diff --git a/advisories/BREW-prowler-CVE-2023-6681.json b/advisories/BREW-prowler-CVE-2023-6681.json index d614529891..769a039cdc 100644 --- a/advisories/BREW-prowler-CVE-2023-6681.json +++ b/advisories/BREW-prowler-CVE-2023-6681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2023-6681", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-cw2r-4p82-qv79", "CVE-2023-6681", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.1", "resource": "jwcrypto", - "resource_purl": "pkg:pypi/jwcrypto@1.5.9" + "resource_purl": "pkg:pypi/jwcrypto@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" } ] diff --git a/advisories/BREW-prowler-CVE-2024-28102.json b/advisories/BREW-prowler-CVE-2024-28102.json index 4d81358d89..9ae1d39f9e 100644 --- a/advisories/BREW-prowler-CVE-2024-28102.json +++ b/advisories/BREW-prowler-CVE-2024-28102.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2024-28102", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-j857-7rvv-vj97", "CVE-2024-28102", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.6", "resource": "jwcrypto", - "resource_purl": "pkg:pypi/jwcrypto@1.5.9" + "resource_purl": "pkg:pypi/jwcrypto@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" } ] diff --git a/advisories/BREW-prowler-CVE-2025-4565.json b/advisories/BREW-prowler-CVE-2025-4565.json index 3dde1682da..f7a40694c1 100644 --- a/advisories/BREW-prowler-CVE-2025-4565.json +++ b/advisories/BREW-prowler-CVE-2025-4565.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2025-4565", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-8qvm-5x2c-j2w7", "CVE-2025-4565", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.31.1", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@7.36.0" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-prowler-CVE-2025-68146.json b/advisories/BREW-prowler-CVE-2025-68146.json index bde6619b1f..c0b13ecdce 100644 --- a/advisories/BREW-prowler-CVE-2025-68146.json +++ b/advisories/BREW-prowler-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2025-68146", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.1", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.4" + "resource_purl": "pkg:pypi/filelock@3.32.5" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" } ] diff --git a/advisories/BREW-prowler-CVE-2026-0994.json b/advisories/BREW-prowler-CVE-2026-0994.json index 90b526f6cf..f7f5989eda 100644 --- a/advisories/BREW-prowler-CVE-2026-0994.json +++ b/advisories/BREW-prowler-CVE-2026-0994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2026-0994", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-7gcm-g887-7qv7", "CVE-2026-0994", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.33.5", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@7.36.0" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-prowler-CVE-2026-22701.json b/advisories/BREW-prowler-CVE-2026-22701.json index ac92db4ab1..ae06e32593 100644 --- a/advisories/BREW-prowler-CVE-2026-22701.json +++ b/advisories/BREW-prowler-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2026-22701", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.3", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.4" + "resource_purl": "pkg:pypi/filelock@3.32.5" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" } ] diff --git a/advisories/BREW-prowler-CVE-2026-39373.json b/advisories/BREW-prowler-CVE-2026-39373.json index 0a5d057da1..5e41763b96 100644 --- a/advisories/BREW-prowler-CVE-2026-39373.json +++ b/advisories/BREW-prowler-CVE-2026-39373.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2026-39373", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-fjrm-76x2-c4q4", "CVE-2026-39373", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.7", "resource": "jwcrypto", - "resource_purl": "pkg:pypi/jwcrypto@1.5.9" + "resource_purl": "pkg:pypi/jwcrypto@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" } ] diff --git a/advisories/BREW-pygitup-CVE-2026-76221.json b/advisories/BREW-pygitup-CVE-2026-76221.json index 5cb43ffbe8..3964ba1af5 100644 --- a/advisories/BREW-pygitup-CVE-2026-76221.json +++ b/advisories/BREW-pygitup-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-pygitup-CVE-2026-76221", "published": "2026-08-20T09:34:40Z", - "modified": "2026-08-20T09:34:40Z", + "modified": "2026-09-04T09:48:58Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pygitup-CVE-2026-76222.json b/advisories/BREW-pygitup-CVE-2026-76222.json index 35091eb1ef..9cf7e4f897 100644 --- a/advisories/BREW-pygitup-CVE-2026-76222.json +++ b/advisories/BREW-pygitup-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-pygitup-CVE-2026-76222", "published": "2026-08-20T09:34:40Z", - "modified": "2026-08-20T09:34:40Z", + "modified": "2026-09-04T09:48:58Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pygitup-CVE-2026-78675.json b/advisories/BREW-pygitup-CVE-2026-78675.json new file mode 100644 index 0000000000..447139418e --- /dev/null +++ b/advisories/BREW-pygitup-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pygitup-CVE-2026-78675", + "published": "2026-09-04T09:50:12Z", + "modified": "2026-09-04T09:50:12Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pygitup", + "purl": "pkg:brew/pygitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.5.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-pygitup-CVE-2026-78676.json b/advisories/BREW-pygitup-CVE-2026-78676.json new file mode 100644 index 0000000000..4993923411 --- /dev/null +++ b/advisories/BREW-pygitup-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pygitup-CVE-2026-78676", + "published": "2026-09-04T09:50:12Z", + "modified": "2026-09-04T09:50:12Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pygitup", + "purl": "pkg:brew/pygitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.5.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-pygitup-CVE-2026-78677.json b/advisories/BREW-pygitup-CVE-2026-78677.json new file mode 100644 index 0000000000..c6e6a8eb17 --- /dev/null +++ b/advisories/BREW-pygitup-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pygitup-CVE-2026-78677", + "published": "2026-09-04T09:50:12Z", + "modified": "2026-09-04T09:50:12Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pygitup", + "purl": "pkg:brew/pygitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.5.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-pygitup-CVE-2026-78678.json b/advisories/BREW-pygitup-CVE-2026-78678.json new file mode 100644 index 0000000000..7a128af791 --- /dev/null +++ b/advisories/BREW-pygitup-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pygitup-CVE-2026-78678", + "published": "2026-09-04T09:50:12Z", + "modified": "2026-09-04T09:50:12Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pygitup", + "purl": "pkg:brew/pygitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.5.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-pygitup-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-pygitup-GHSA-hmq2-w58f-27jc.json index 6766129c93..4f2923f804 100644 --- a/advisories/BREW-pygitup-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-pygitup-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-pygitup-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:29:36Z", - "modified": "2026-08-29T09:34:20Z", + "modified": "2026-09-04T09:48:58Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pygitup-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-pygitup-GHSA-jm78-9fvv-mhgr.json index 0b5d7c986c..ad2a80a77f 100644 --- a/advisories/BREW-pygitup-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-pygitup-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-pygitup-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:29:36Z", - "modified": "2026-08-29T09:34:20Z", + "modified": "2026-09-04T09:48:58Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-renovate-CVE-2024-58376.json b/advisories/BREW-renovate-CVE-2024-58376.json index 5008482877..e9fb39e7c8 100644 --- a/advisories/BREW-renovate-CVE-2024-58376.json +++ b/advisories/BREW-renovate-CVE-2024-58376.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2024-58376", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2024-58376", "GHSA-rqgv-292v-5qgr" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76226.json b/advisories/BREW-renovate-CVE-2026-76226.json index c66a081b3c..80d6603f62 100644 --- a/advisories/BREW-renovate-CVE-2026-76226.json +++ b/advisories/BREW-renovate-CVE-2026-76226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76226", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76226", "GHSA-5vjq-5jmg-39xq" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76227.json b/advisories/BREW-renovate-CVE-2026-76227.json index 750ee95faf..357ad82eba 100644 --- a/advisories/BREW-renovate-CVE-2026-76227.json +++ b/advisories/BREW-renovate-CVE-2026-76227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76227", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76227", "GHSA-8wc6-vgrq-x6cf" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76228.json b/advisories/BREW-renovate-CVE-2026-76228.json index 36ab764ca0..fb90465177 100644 --- a/advisories/BREW-renovate-CVE-2026-76228.json +++ b/advisories/BREW-renovate-CVE-2026-76228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76228", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76228", "GHSA-pfq2-hh62-7m96" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76229.json b/advisories/BREW-renovate-CVE-2026-76229.json index 06ec7ffb73..0b54d4c1f3 100644 --- a/advisories/BREW-renovate-CVE-2026-76229.json +++ b/advisories/BREW-renovate-CVE-2026-76229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76229", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76229", "GHSA-xv56-3wq5-9997" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76230.json b/advisories/BREW-renovate-CVE-2026-76230.json index 2c03b09e76..90d83959e2 100644 --- a/advisories/BREW-renovate-CVE-2026-76230.json +++ b/advisories/BREW-renovate-CVE-2026-76230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76230", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76230", "GHSA-fr4j-65pv-gjjj" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76231.json b/advisories/BREW-renovate-CVE-2026-76231.json index 608d46d983..fd3cd3010e 100644 --- a/advisories/BREW-renovate-CVE-2026-76231.json +++ b/advisories/BREW-renovate-CVE-2026-76231.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76231", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76231", "GHSA-36j9-mx87-2cff" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76232.json b/advisories/BREW-renovate-CVE-2026-76232.json index 7be83f271c..37215d70ef 100644 --- a/advisories/BREW-renovate-CVE-2026-76232.json +++ b/advisories/BREW-renovate-CVE-2026-76232.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76232", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76232", "GHSA-3f44-xw83-3pmg" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76233.json b/advisories/BREW-renovate-CVE-2026-76233.json index b84ae5db1c..dbc6f35514 100644 --- a/advisories/BREW-renovate-CVE-2026-76233.json +++ b/advisories/BREW-renovate-CVE-2026-76233.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76233", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76233", "GHSA-xjr7-3c3g-m763" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-36j9-mx87-2cff.json b/advisories/BREW-renovate-GHSA-36j9-mx87-2cff.json index 51e2195568..e847e864f8 100644 --- a/advisories/BREW-renovate-GHSA-36j9-mx87-2cff.json +++ b/advisories/BREW-renovate-GHSA-36j9-mx87-2cff.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-36j9-mx87-2cff", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-36j9-mx87-2cff", "CVE-2026-76231" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json b/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json index 972e7ef019..7c70ef11df 100644 --- a/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json +++ b/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-36rh-ggpr-j3gj", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-36rh-ggpr-j3gj" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-3f44-xw83-3pmg.json b/advisories/BREW-renovate-GHSA-3f44-xw83-3pmg.json index dd7cc3ef2e..292dd58530 100644 --- a/advisories/BREW-renovate-GHSA-3f44-xw83-3pmg.json +++ b/advisories/BREW-renovate-GHSA-3f44-xw83-3pmg.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-3f44-xw83-3pmg", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-3f44-xw83-3pmg", "CVE-2026-76232" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-5vjq-5jmg-39xq.json b/advisories/BREW-renovate-GHSA-5vjq-5jmg-39xq.json index c989a1bb43..3f3fdf1260 100644 --- a/advisories/BREW-renovate-GHSA-5vjq-5jmg-39xq.json +++ b/advisories/BREW-renovate-GHSA-5vjq-5jmg-39xq.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-5vjq-5jmg-39xq", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-5vjq-5jmg-39xq", "CVE-2026-76226" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-8wc6-vgrq-x6cf.json b/advisories/BREW-renovate-GHSA-8wc6-vgrq-x6cf.json index fb3934c4b2..fc873f22e2 100644 --- a/advisories/BREW-renovate-GHSA-8wc6-vgrq-x6cf.json +++ b/advisories/BREW-renovate-GHSA-8wc6-vgrq-x6cf.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-8wc6-vgrq-x6cf", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-8wc6-vgrq-x6cf", "CVE-2026-76227" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-fr4j-65pv-gjjj.json b/advisories/BREW-renovate-GHSA-fr4j-65pv-gjjj.json index 7ecde79c6f..0356150911 100644 --- a/advisories/BREW-renovate-GHSA-fr4j-65pv-gjjj.json +++ b/advisories/BREW-renovate-GHSA-fr4j-65pv-gjjj.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-fr4j-65pv-gjjj", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-fr4j-65pv-gjjj", "CVE-2026-76230" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-pfq2-hh62-7m96.json b/advisories/BREW-renovate-GHSA-pfq2-hh62-7m96.json index d66462955b..829f313d43 100644 --- a/advisories/BREW-renovate-GHSA-pfq2-hh62-7m96.json +++ b/advisories/BREW-renovate-GHSA-pfq2-hh62-7m96.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-pfq2-hh62-7m96", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-pfq2-hh62-7m96", "CVE-2026-76228" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-rqgv-292v-5qgr.json b/advisories/BREW-renovate-GHSA-rqgv-292v-5qgr.json index 7e15d58db1..3ff82532a1 100644 --- a/advisories/BREW-renovate-GHSA-rqgv-292v-5qgr.json +++ b/advisories/BREW-renovate-GHSA-rqgv-292v-5qgr.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-rqgv-292v-5qgr", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-rqgv-292v-5qgr", "CVE-2024-58376" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json b/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json index 1c12854210..77c87c56ad 100644 --- a/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json +++ b/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-v7x3-7hw7-pcjg", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-v7x3-7hw7-pcjg" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-xjr7-3c3g-m763.json b/advisories/BREW-renovate-GHSA-xjr7-3c3g-m763.json index 58d7204929..9211efcda7 100644 --- a/advisories/BREW-renovate-GHSA-xjr7-3c3g-m763.json +++ b/advisories/BREW-renovate-GHSA-xjr7-3c3g-m763.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-xjr7-3c3g-m763", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-xjr7-3c3g-m763", "CVE-2026-76233" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-xv56-3wq5-9997.json b/advisories/BREW-renovate-GHSA-xv56-3wq5-9997.json index 468fed979e..7d0e63e972 100644 --- a/advisories/BREW-renovate-GHSA-xv56-3wq5-9997.json +++ b/advisories/BREW-renovate-GHSA-xv56-3wq5-9997.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-xv56-3wq5-9997", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-xv56-3wq5-9997", "CVE-2026-76229" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-safety-CVE-2026-62384.json b/advisories/BREW-safety-CVE-2026-62384.json new file mode 100644 index 0000000000..ac8d6a3c75 --- /dev/null +++ b/advisories/BREW-safety-CVE-2026-62384.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-safety-CVE-2026-62384", + "published": "2026-09-04T09:59:23Z", + "modified": "2026-09-04T09:59:23Z", + "upstream": [ + "PYSEC-2026-3789", + "CVE-2026-62384", + "GHSA-f833-7jw8-xwrv" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "safety", + "purl": "pkg:brew/safety" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.8.1_2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.10.2", + "resource": "nltk", + "resource_purl": "pkg:pypi/nltk@3.10.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + } + ] + }, + "details": "NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/nltk-framenetcorpusreader-symlink-sandbox-bypass-before" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv" + } + ] +} diff --git a/advisories/BREW-safety-CVE-2026-71514.json b/advisories/BREW-safety-CVE-2026-71514.json index 195256b2e7..00eda4a728 100644 --- a/advisories/BREW-safety-CVE-2026-71514.json +++ b/advisories/BREW-safety-CVE-2026-71514.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-safety-CVE-2026-71514", "published": "2026-09-03T10:05:22Z", - "modified": "2026-09-03T10:05:22Z", + "modified": "2026-09-04T09:57:44Z", "upstream": [ "GHSA-cv22-g7mw-8v73", - "CVE-2026-71514" + "CVE-2026-71514", + "PYSEC-2026-3790" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-shallow-backup-CVE-2026-76221.json b/advisories/BREW-shallow-backup-CVE-2026-76221.json index 6cfc1052b8..3b8d40c005 100644 --- a/advisories/BREW-shallow-backup-CVE-2026-76221.json +++ b/advisories/BREW-shallow-backup-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-shallow-backup-CVE-2026-76221", "published": "2026-08-20T09:38:52Z", - "modified": "2026-08-20T09:38:52Z", + "modified": "2026-09-04T10:00:38Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-shallow-backup-CVE-2026-76222.json b/advisories/BREW-shallow-backup-CVE-2026-76222.json index 5587ff8977..5c3192a683 100644 --- a/advisories/BREW-shallow-backup-CVE-2026-76222.json +++ b/advisories/BREW-shallow-backup-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-shallow-backup-CVE-2026-76222", "published": "2026-08-20T09:38:52Z", - "modified": "2026-08-20T09:38:52Z", + "modified": "2026-09-04T10:00:38Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-shallow-backup-CVE-2026-78675.json b/advisories/BREW-shallow-backup-CVE-2026-78675.json new file mode 100644 index 0000000000..7ba7622e0e --- /dev/null +++ b/advisories/BREW-shallow-backup-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-shallow-backup-CVE-2026-78675", + "published": "2026-09-04T10:00:38Z", + "modified": "2026-09-04T10:00:38Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "shallow-backup", + "purl": "pkg:brew/shallow-backup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-shallow-backup-CVE-2026-78676.json b/advisories/BREW-shallow-backup-CVE-2026-78676.json new file mode 100644 index 0000000000..f4fac87606 --- /dev/null +++ b/advisories/BREW-shallow-backup-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-shallow-backup-CVE-2026-78676", + "published": "2026-09-04T10:00:38Z", + "modified": "2026-09-04T10:00:38Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "shallow-backup", + "purl": "pkg:brew/shallow-backup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-shallow-backup-CVE-2026-78677.json b/advisories/BREW-shallow-backup-CVE-2026-78677.json new file mode 100644 index 0000000000..a636f99e97 --- /dev/null +++ b/advisories/BREW-shallow-backup-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-shallow-backup-CVE-2026-78677", + "published": "2026-09-04T10:00:38Z", + "modified": "2026-09-04T10:00:38Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "shallow-backup", + "purl": "pkg:brew/shallow-backup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-shallow-backup-CVE-2026-78678.json b/advisories/BREW-shallow-backup-CVE-2026-78678.json new file mode 100644 index 0000000000..2cf6358b53 --- /dev/null +++ b/advisories/BREW-shallow-backup-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-shallow-backup-CVE-2026-78678", + "published": "2026-09-04T10:00:38Z", + "modified": "2026-09-04T10:00:38Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "shallow-backup", + "purl": "pkg:brew/shallow-backup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-shallow-backup-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-shallow-backup-GHSA-hmq2-w58f-27jc.json index 9deb38e57e..66a74c481d 100644 --- a/advisories/BREW-shallow-backup-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-shallow-backup-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-shallow-backup-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:34:37Z", - "modified": "2026-08-29T09:41:40Z", + "modified": "2026-09-04T10:00:38Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-shallow-backup-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-shallow-backup-GHSA-jm78-9fvv-mhgr.json index b48e35e1fa..6fa397a8aa 100644 --- a/advisories/BREW-shallow-backup-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-shallow-backup-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-shallow-backup-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:34:37Z", - "modified": "2026-08-29T09:41:40Z", + "modified": "2026-09-04T10:00:38Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakemake-CVE-2026-76221.json b/advisories/BREW-snakemake-CVE-2026-76221.json index a1c5397afc..6c47380fc9 100644 --- a/advisories/BREW-snakemake-CVE-2026-76221.json +++ b/advisories/BREW-snakemake-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snakemake-CVE-2026-76221", "published": "2026-08-20T09:39:58Z", - "modified": "2026-08-28T13:18:13Z", + "modified": "2026-09-04T10:03:26Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakemake-CVE-2026-76222.json b/advisories/BREW-snakemake-CVE-2026-76222.json index 76f8c17649..5ff70ac27e 100644 --- a/advisories/BREW-snakemake-CVE-2026-76222.json +++ b/advisories/BREW-snakemake-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snakemake-CVE-2026-76222", "published": "2026-08-20T09:39:58Z", - "modified": "2026-08-28T13:18:13Z", + "modified": "2026-09-04T10:03:26Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakemake-CVE-2026-78675.json b/advisories/BREW-snakemake-CVE-2026-78675.json new file mode 100644 index 0000000000..19a1d9b5b4 --- /dev/null +++ b/advisories/BREW-snakemake-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snakemake-CVE-2026-78675", + "published": "2026-09-04T10:04:58Z", + "modified": "2026-09-04T10:04:58Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snakemake", + "purl": "pkg:brew/snakemake" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.25.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-snakemake-CVE-2026-78676.json b/advisories/BREW-snakemake-CVE-2026-78676.json new file mode 100644 index 0000000000..6fd33bf3bd --- /dev/null +++ b/advisories/BREW-snakemake-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snakemake-CVE-2026-78676", + "published": "2026-09-04T10:04:58Z", + "modified": "2026-09-04T10:04:58Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snakemake", + "purl": "pkg:brew/snakemake" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.25.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-snakemake-CVE-2026-78677.json b/advisories/BREW-snakemake-CVE-2026-78677.json new file mode 100644 index 0000000000..68b8327797 --- /dev/null +++ b/advisories/BREW-snakemake-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snakemake-CVE-2026-78677", + "published": "2026-09-04T10:04:58Z", + "modified": "2026-09-04T10:04:58Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snakemake", + "purl": "pkg:brew/snakemake" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.25.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-snakemake-CVE-2026-78678.json b/advisories/BREW-snakemake-CVE-2026-78678.json new file mode 100644 index 0000000000..f8d6bc7879 --- /dev/null +++ b/advisories/BREW-snakemake-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snakemake-CVE-2026-78678", + "published": "2026-09-04T10:04:58Z", + "modified": "2026-09-04T10:04:58Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snakemake", + "purl": "pkg:brew/snakemake" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.25.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-snakemake-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-snakemake-GHSA-hmq2-w58f-27jc.json index dcb1003fa8..522900e74b 100644 --- a/advisories/BREW-snakemake-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-snakemake-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snakemake-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-29T09:43:05Z", + "modified": "2026-09-04T10:03:26Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakemake-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-snakemake-GHSA-jm78-9fvv-mhgr.json index d685edad09..b16d783c6b 100644 --- a/advisories/BREW-snakemake-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-snakemake-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snakemake-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-29T09:43:05Z", + "modified": "2026-09-04T10:03:26Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-76221.json b/advisories/BREW-snowflake-cli-CVE-2026-76221.json index 065ab2e3d1..e8ca8daf2c 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-76221.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-76221", "published": "2026-08-20T09:40:01Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-04T10:05:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-76222.json b/advisories/BREW-snowflake-cli-CVE-2026-76222.json index 26138ad092..41a4884164 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-76222.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-76222", "published": "2026-08-20T09:40:01Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-04T10:05:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78675.json b/advisories/BREW-snowflake-cli-CVE-2026-78675.json new file mode 100644 index 0000000000..c3082d9d11 --- /dev/null +++ b/advisories/BREW-snowflake-cli-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snowflake-cli-CVE-2026-78675", + "published": "2026-09-04T10:05:02Z", + "modified": "2026-09-04T10:05:02Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snowflake-cli", + "purl": "pkg:brew/snowflake-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78676.json b/advisories/BREW-snowflake-cli-CVE-2026-78676.json new file mode 100644 index 0000000000..bc87c1e707 --- /dev/null +++ b/advisories/BREW-snowflake-cli-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snowflake-cli-CVE-2026-78676", + "published": "2026-09-04T10:05:02Z", + "modified": "2026-09-04T10:05:02Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snowflake-cli", + "purl": "pkg:brew/snowflake-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78677.json b/advisories/BREW-snowflake-cli-CVE-2026-78677.json new file mode 100644 index 0000000000..98dacc503f --- /dev/null +++ b/advisories/BREW-snowflake-cli-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snowflake-cli-CVE-2026-78677", + "published": "2026-09-04T10:05:02Z", + "modified": "2026-09-04T10:05:02Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snowflake-cli", + "purl": "pkg:brew/snowflake-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78678.json b/advisories/BREW-snowflake-cli-CVE-2026-78678.json new file mode 100644 index 0000000000..2129890bb1 --- /dev/null +++ b/advisories/BREW-snowflake-cli-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snowflake-cli-CVE-2026-78678", + "published": "2026-09-04T10:05:02Z", + "modified": "2026-09-04T10:05:02Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snowflake-cli", + "purl": "pkg:brew/snowflake-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-snowflake-cli-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-snowflake-cli-GHSA-hmq2-w58f-27jc.json index 615d971abc..81ff0f7c2c 100644 --- a/advisories/BREW-snowflake-cli-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-snowflake-cli-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-29T09:45:05Z", + "modified": "2026-09-04T10:05:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-snowflake-cli-GHSA-jm78-9fvv-mhgr.json index de278be112..9041b680af 100644 --- a/advisories/BREW-snowflake-cli-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-snowflake-cli-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-29T09:45:05Z", + "modified": "2026-09-04T10:05:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-standardebooks-CVE-2026-76221.json b/advisories/BREW-standardebooks-CVE-2026-76221.json index ac78029432..a5958cfd30 100644 --- a/advisories/BREW-standardebooks-CVE-2026-76221.json +++ b/advisories/BREW-standardebooks-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-standardebooks-CVE-2026-76221", "published": "2026-08-20T09:44:27Z", - "modified": "2026-08-20T09:44:27Z", + "modified": "2026-09-04T10:10:36Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-standardebooks-CVE-2026-76222.json b/advisories/BREW-standardebooks-CVE-2026-76222.json index 89a7519311..709facb419 100644 --- a/advisories/BREW-standardebooks-CVE-2026-76222.json +++ b/advisories/BREW-standardebooks-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-standardebooks-CVE-2026-76222", "published": "2026-08-20T09:44:27Z", - "modified": "2026-08-20T09:44:27Z", + "modified": "2026-09-04T10:10:36Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-standardebooks-CVE-2026-78675.json b/advisories/BREW-standardebooks-CVE-2026-78675.json new file mode 100644 index 0000000000..9fa18c7669 --- /dev/null +++ b/advisories/BREW-standardebooks-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-standardebooks-CVE-2026-78675", + "published": "2026-09-04T10:10:36Z", + "modified": "2026-09-04T10:10:36Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "standardebooks", + "purl": "pkg:brew/standardebooks" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.54" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-standardebooks-CVE-2026-78676.json b/advisories/BREW-standardebooks-CVE-2026-78676.json new file mode 100644 index 0000000000..c9d11bb753 --- /dev/null +++ b/advisories/BREW-standardebooks-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-standardebooks-CVE-2026-78676", + "published": "2026-09-04T10:10:36Z", + "modified": "2026-09-04T10:10:36Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "standardebooks", + "purl": "pkg:brew/standardebooks" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.54" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-standardebooks-CVE-2026-78677.json b/advisories/BREW-standardebooks-CVE-2026-78677.json new file mode 100644 index 0000000000..897092ec8b --- /dev/null +++ b/advisories/BREW-standardebooks-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-standardebooks-CVE-2026-78677", + "published": "2026-09-04T10:10:36Z", + "modified": "2026-09-04T10:10:36Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "standardebooks", + "purl": "pkg:brew/standardebooks" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.54" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-standardebooks-CVE-2026-78678.json b/advisories/BREW-standardebooks-CVE-2026-78678.json new file mode 100644 index 0000000000..1df2e1fba7 --- /dev/null +++ b/advisories/BREW-standardebooks-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-standardebooks-CVE-2026-78678", + "published": "2026-09-04T10:10:36Z", + "modified": "2026-09-04T10:10:36Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "standardebooks", + "purl": "pkg:brew/standardebooks" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.54" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-standardebooks-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-standardebooks-GHSA-hmq2-w58f-27jc.json index b5b44225d0..1020f1afa2 100644 --- a/advisories/BREW-standardebooks-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-standardebooks-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-standardebooks-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:41:08Z", - "modified": "2026-08-29T09:50:09Z", + "modified": "2026-09-04T10:10:36Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-standardebooks-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-standardebooks-GHSA-jm78-9fvv-mhgr.json index e0746778e5..ffa240f3cc 100644 --- a/advisories/BREW-standardebooks-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-standardebooks-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-standardebooks-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:41:08Z", - "modified": "2026-08-29T09:50:09Z", + "modified": "2026-09-04T10:10:36Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tach-CVE-2026-76221.json b/advisories/BREW-tach-CVE-2026-76221.json index 9a9f2003d2..3105536415 100644 --- a/advisories/BREW-tach-CVE-2026-76221.json +++ b/advisories/BREW-tach-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tach-CVE-2026-76221", "published": "2026-08-20T09:45:21Z", - "modified": "2026-08-20T09:45:21Z", + "modified": "2026-09-04T10:11:45Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tach-CVE-2026-76222.json b/advisories/BREW-tach-CVE-2026-76222.json index 44741004bf..94343ca10a 100644 --- a/advisories/BREW-tach-CVE-2026-76222.json +++ b/advisories/BREW-tach-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tach-CVE-2026-76222", "published": "2026-08-20T09:45:21Z", - "modified": "2026-08-20T09:45:21Z", + "modified": "2026-09-04T10:11:45Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tach-CVE-2026-78675.json b/advisories/BREW-tach-CVE-2026-78675.json new file mode 100644 index 0000000000..b514ef1102 --- /dev/null +++ b/advisories/BREW-tach-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tach-CVE-2026-78675", + "published": "2026-09-04T10:11:45Z", + "modified": "2026-09-04T10:11:45Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tach", + "purl": "pkg:brew/tach" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-tach-CVE-2026-78676.json b/advisories/BREW-tach-CVE-2026-78676.json new file mode 100644 index 0000000000..1950ca22a2 --- /dev/null +++ b/advisories/BREW-tach-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tach-CVE-2026-78676", + "published": "2026-09-04T10:11:45Z", + "modified": "2026-09-04T10:11:45Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tach", + "purl": "pkg:brew/tach" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-tach-CVE-2026-78677.json b/advisories/BREW-tach-CVE-2026-78677.json new file mode 100644 index 0000000000..7beda427ee --- /dev/null +++ b/advisories/BREW-tach-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tach-CVE-2026-78677", + "published": "2026-09-04T10:11:45Z", + "modified": "2026-09-04T10:11:45Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tach", + "purl": "pkg:brew/tach" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-tach-CVE-2026-78678.json b/advisories/BREW-tach-CVE-2026-78678.json new file mode 100644 index 0000000000..740653d1c6 --- /dev/null +++ b/advisories/BREW-tach-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tach-CVE-2026-78678", + "published": "2026-09-04T10:11:45Z", + "modified": "2026-09-04T10:11:45Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tach", + "purl": "pkg:brew/tach" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-tach-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-tach-GHSA-hmq2-w58f-27jc.json index a2da37df22..fcbba4bf31 100644 --- a/advisories/BREW-tach-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-tach-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tach-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:42:17Z", - "modified": "2026-08-29T09:51:16Z", + "modified": "2026-09-04T10:11:45Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tach-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-tach-GHSA-jm78-9fvv-mhgr.json index 3c64a69ccb..e18d200e31 100644 --- a/advisories/BREW-tach-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-tach-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tach-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:42:17Z", - "modified": "2026-08-29T09:51:16Z", + "modified": "2026-09-04T10:11:45Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-76221.json b/advisories/BREW-tartufo-CVE-2026-76221.json index f9d987aa29..23b1f25a41 100644 --- a/advisories/BREW-tartufo-CVE-2026-76221.json +++ b/advisories/BREW-tartufo-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76221", "published": "2026-08-20T09:45:22Z", - "modified": "2026-08-20T09:45:22Z", + "modified": "2026-09-04T10:12:20Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-76222.json b/advisories/BREW-tartufo-CVE-2026-76222.json index 654d8d72fb..cdd41d2174 100644 --- a/advisories/BREW-tartufo-CVE-2026-76222.json +++ b/advisories/BREW-tartufo-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76222", "published": "2026-08-20T09:45:22Z", - "modified": "2026-08-20T09:45:22Z", + "modified": "2026-09-04T10:12:20Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-78675.json b/advisories/BREW-tartufo-CVE-2026-78675.json new file mode 100644 index 0000000000..82a37e2e09 --- /dev/null +++ b/advisories/BREW-tartufo-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tartufo-CVE-2026-78675", + "published": "2026-09-04T10:12:20Z", + "modified": "2026-09-04T10:12:20Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tartufo", + "purl": "pkg:brew/tartufo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-tartufo-CVE-2026-78676.json b/advisories/BREW-tartufo-CVE-2026-78676.json new file mode 100644 index 0000000000..d4070e4ec4 --- /dev/null +++ b/advisories/BREW-tartufo-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tartufo-CVE-2026-78676", + "published": "2026-09-04T10:12:20Z", + "modified": "2026-09-04T10:12:20Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tartufo", + "purl": "pkg:brew/tartufo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-tartufo-CVE-2026-78677.json b/advisories/BREW-tartufo-CVE-2026-78677.json new file mode 100644 index 0000000000..0e8fe64157 --- /dev/null +++ b/advisories/BREW-tartufo-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tartufo-CVE-2026-78677", + "published": "2026-09-04T10:12:20Z", + "modified": "2026-09-04T10:12:20Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tartufo", + "purl": "pkg:brew/tartufo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-tartufo-CVE-2026-78678.json b/advisories/BREW-tartufo-CVE-2026-78678.json new file mode 100644 index 0000000000..a4cfa94a8b --- /dev/null +++ b/advisories/BREW-tartufo-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tartufo-CVE-2026-78678", + "published": "2026-09-04T10:12:20Z", + "modified": "2026-09-04T10:12:20Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tartufo", + "purl": "pkg:brew/tartufo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-tartufo-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-tartufo-GHSA-hmq2-w58f-27jc.json index 9a739e28a1..72b5fd9501 100644 --- a/advisories/BREW-tartufo-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-tartufo-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:42:18Z", - "modified": "2026-08-29T09:51:56Z", + "modified": "2026-09-04T10:12:20Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-tartufo-GHSA-jm78-9fvv-mhgr.json index 795392f397..ed3533afc8 100644 --- a/advisories/BREW-tartufo-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-tartufo-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:42:18Z", - "modified": "2026-08-29T09:51:56Z", + "modified": "2026-09-04T10:12:20Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tern-CVE-2026-76221.json b/advisories/BREW-tern-CVE-2026-76221.json index 72adaaacd2..efc9308995 100644 --- a/advisories/BREW-tern-CVE-2026-76221.json +++ b/advisories/BREW-tern-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tern-CVE-2026-76221", "published": "2026-08-20T09:45:59Z", - "modified": "2026-08-20T09:45:59Z", + "modified": "2026-09-04T10:12:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tern-CVE-2026-76222.json b/advisories/BREW-tern-CVE-2026-76222.json index 9cb112edba..18ee8022a4 100644 --- a/advisories/BREW-tern-CVE-2026-76222.json +++ b/advisories/BREW-tern-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tern-CVE-2026-76222", "published": "2026-08-20T09:45:59Z", - "modified": "2026-08-20T09:45:59Z", + "modified": "2026-09-04T10:12:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tern-CVE-2026-78675.json b/advisories/BREW-tern-CVE-2026-78675.json new file mode 100644 index 0000000000..df79f6d30b --- /dev/null +++ b/advisories/BREW-tern-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tern-CVE-2026-78675", + "published": "2026-09-04T10:12:29Z", + "modified": "2026-09-04T10:12:29Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tern", + "purl": "pkg:brew/tern" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.45" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-tern-CVE-2026-78676.json b/advisories/BREW-tern-CVE-2026-78676.json new file mode 100644 index 0000000000..7ff39a083e --- /dev/null +++ b/advisories/BREW-tern-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tern-CVE-2026-78676", + "published": "2026-09-04T10:12:29Z", + "modified": "2026-09-04T10:12:29Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tern", + "purl": "pkg:brew/tern" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.45" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-tern-CVE-2026-78677.json b/advisories/BREW-tern-CVE-2026-78677.json new file mode 100644 index 0000000000..b5e00ea56e --- /dev/null +++ b/advisories/BREW-tern-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tern-CVE-2026-78677", + "published": "2026-09-04T10:12:29Z", + "modified": "2026-09-04T10:12:29Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tern", + "purl": "pkg:brew/tern" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.45" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-tern-CVE-2026-78678.json b/advisories/BREW-tern-CVE-2026-78678.json new file mode 100644 index 0000000000..e8664c85b0 --- /dev/null +++ b/advisories/BREW-tern-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tern-CVE-2026-78678", + "published": "2026-09-04T10:12:29Z", + "modified": "2026-09-04T10:12:29Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tern", + "purl": "pkg:brew/tern" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.45" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-tern-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-tern-GHSA-hmq2-w58f-27jc.json index 62e706bdab..569625ba97 100644 --- a/advisories/BREW-tern-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-tern-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tern-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:43:04Z", - "modified": "2026-08-29T09:52:04Z", + "modified": "2026-09-04T10:12:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tern-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-tern-GHSA-jm78-9fvv-mhgr.json index 1163b9735a..85e020b210 100644 --- a/advisories/BREW-tern-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-tern-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tern-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:43:04Z", - "modified": "2026-08-29T09:52:04Z", + "modified": "2026-09-04T10:12:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI",