From b65711293b3cd53f95908ae3a46343790dc2d374 Mon Sep 17 00:00:00 2001 From: BrewTestBot <1589480+BrewTestBot@users.noreply.github.com> Date: Fri, 4 Sep 2026 10:29:09 +0000 Subject: [PATCH] Matched advisory candidates Base: dc4b78399ffa7f9ccfc235f282a9df24d419e249 --- advisories/BREW-acronym-CVE-2026-62384.json | 72 +++++++++++++ advisories/BREW-acronym-CVE-2026-71514.json | 13 ++- advisories/BREW-aider-CVE-2026-76221.json | 13 ++- advisories/BREW-aider-CVE-2026-76222.json | 13 ++- advisories/BREW-aider-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-aider-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-aider-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-aider-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-aider-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-aider-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-allure-CVE-2026-55846.json | 6 +- advisories/BREW-apm-CVE-2026-76221.json | 13 ++- advisories/BREW-apm-CVE-2026-76222.json | 13 ++- advisories/BREW-apm-CVE-2026-78675.json | 72 +++++++++++++ advisories/BREW-apm-CVE-2026-78676.json | 72 +++++++++++++ advisories/BREW-apm-CVE-2026-78677.json | 72 +++++++++++++ advisories/BREW-apm-CVE-2026-78678.json | 72 +++++++++++++ advisories/BREW-apm-GHSA-hmq2-w58f-27jc.json | 13 ++- advisories/BREW-apm-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-btcli-CVE-2026-76221.json | 13 ++- advisories/BREW-btcli-CVE-2026-76222.json | 13 ++- advisories/BREW-btcli-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-btcli-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-btcli-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-btcli-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-btcli-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-btcli-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-cf2tf-CVE-2026-76221.json | 13 ++- advisories/BREW-cf2tf-CVE-2026-76222.json | 13 ++- advisories/BREW-cf2tf-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-cf2tf-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-cf2tf-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-cf2tf-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-cf2tf-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-cf2tf-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-checkov-CVE-2026-76221.json | 13 ++- advisories/BREW-checkov-CVE-2026-76222.json | 13 ++- advisories/BREW-checkov-CVE-2026-78675.json | 72 +++++++++++++ advisories/BREW-checkov-CVE-2026-78676.json | 72 +++++++++++++ advisories/BREW-checkov-CVE-2026-78677.json | 72 +++++++++++++ advisories/BREW-checkov-CVE-2026-78678.json | 72 +++++++++++++ .../BREW-checkov-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-checkov-GHSA-jm78-9fvv-mhgr.json | 13 ++- ...-claude-code-templates-CVE-2026-73222.json | 81 ++++++++++++++ advisories/BREW-cobo-cli-CVE-2026-76221.json | 13 ++- advisories/BREW-cobo-cli-CVE-2026-76222.json | 13 ++- advisories/BREW-cobo-cli-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-cobo-cli-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-cobo-cli-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-cobo-cli-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-cobo-cli-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-cobo-cli-GHSA-jm78-9fvv-mhgr.json | 13 ++- .../BREW-conda-lock-CVE-2026-76221.json | 13 ++- .../BREW-conda-lock-CVE-2026-76222.json | 13 ++- .../BREW-conda-lock-CVE-2026-78675.json | 69 ++++++++++++ .../BREW-conda-lock-CVE-2026-78676.json | 69 ++++++++++++ .../BREW-conda-lock-CVE-2026-78677.json | 69 ++++++++++++ .../BREW-conda-lock-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-conda-lock-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-conda-lock-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-cruft-CVE-2026-76221.json | 13 ++- advisories/BREW-cruft-CVE-2026-76222.json | 13 ++- advisories/BREW-cruft-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-cruft-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-cruft-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-cruft-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-cruft-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-cruft-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-cycode-CVE-2026-76221.json | 13 ++- advisories/BREW-cycode-CVE-2026-76222.json | 13 ++- advisories/BREW-cycode-CVE-2026-78675.json | 72 +++++++++++++ advisories/BREW-cycode-CVE-2026-78676.json | 72 +++++++++++++ advisories/BREW-cycode-CVE-2026-78677.json | 72 +++++++++++++ advisories/BREW-cycode-CVE-2026-78678.json | 72 +++++++++++++ .../BREW-cycode-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-cycode-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-djlint-CVE-2026-7246.json | 8 +- advisories/BREW-dstack-CVE-2026-76221.json | 13 ++- advisories/BREW-dstack-CVE-2026-76222.json | 13 ++- advisories/BREW-dstack-CVE-2026-78675.json | 72 +++++++++++++ advisories/BREW-dstack-CVE-2026-78676.json | 72 +++++++++++++ advisories/BREW-dstack-CVE-2026-78677.json | 72 +++++++++++++ advisories/BREW-dstack-CVE-2026-78678.json | 72 +++++++++++++ .../BREW-dstack-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-dstack-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-dvc-CVE-2026-76221.json | 13 ++- advisories/BREW-dvc-CVE-2026-76222.json | 13 ++- advisories/BREW-dvc-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-dvc-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-dvc-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-dvc-CVE-2026-78678.json | 69 ++++++++++++ advisories/BREW-dvc-GHSA-hmq2-w58f-27jc.json | 13 ++- advisories/BREW-dvc-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-esptool-CVE-2015-8557.json | 12 +-- advisories/BREW-esptool-CVE-2018-1000518.json | 93 ++++++++++++++++ advisories/BREW-esptool-CVE-2021-20270.json | 12 +-- advisories/BREW-esptool-CVE-2021-27291.json | 12 +-- advisories/BREW-esptool-CVE-2021-33880.json | 101 ++++++++++++++++++ advisories/BREW-esptool-CVE-2022-40896.json | 12 +-- advisories/BREW-esptool-CVE-2023-46894.json | 10 +- advisories/BREW-esptool-CVE-2026-4539.json | 12 +-- advisories/BREW-esptool-CVE-2026-7246.json | 8 +- advisories/BREW-fastmcp-CVE-2025-62800.json | 10 +- advisories/BREW-fastmcp-CVE-2025-62801.json | 10 +- advisories/BREW-fastmcp-CVE-2025-64340.json | 10 +- advisories/BREW-fastmcp-CVE-2025-69196.json | 10 +- advisories/BREW-fastmcp-CVE-2026-27124.json | 10 +- advisories/BREW-fastmcp-CVE-2026-32871.json | 10 +- .../BREW-fastmcp-GHSA-c2jp-c369-7pvx.json | 6 +- .../BREW-fastmcp-GHSA-rcfx-77hg-w2wv.json | 6 +- .../BREW-fdroidserver-CVE-2026-76221.json | 13 ++- .../BREW-fdroidserver-CVE-2026-76222.json | 13 ++- .../BREW-fdroidserver-CVE-2026-78675.json | 69 ++++++++++++ .../BREW-fdroidserver-CVE-2026-78676.json | 69 ++++++++++++ .../BREW-fdroidserver-CVE-2026-78677.json | 69 ++++++++++++ .../BREW-fdroidserver-CVE-2026-78678.json | 69 ++++++++++++ ...BREW-fdroidserver-GHSA-hmq2-w58f-27jc.json | 13 ++- ...BREW-fdroidserver-GHSA-jm78-9fvv-mhgr.json | 13 ++- .../BREW-firebase-cli-CVE-2024-4128.json | 6 +- advisories/BREW-gitup-CVE-2026-76221.json | 13 ++- advisories/BREW-gitup-CVE-2026-76222.json | 13 ++- advisories/BREW-gitup-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-gitup-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-gitup-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-gitup-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-gitup-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-gitup-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-glances-CVE-2024-33663.json | 5 +- advisories/BREW-gptline-CVE-2026-62384.json | 72 +++++++++++++ advisories/BREW-gptline-CVE-2026-71514.json | 13 ++- advisories/BREW-harlequin-CVE-2026-7246.json | 8 +- advisories/BREW-jiratui-CVE-2026-76221.json | 13 ++- advisories/BREW-jiratui-CVE-2026-76222.json | 13 ++- advisories/BREW-jiratui-CVE-2026-78675.json | 72 +++++++++++++ advisories/BREW-jiratui-CVE-2026-78676.json | 72 +++++++++++++ advisories/BREW-jiratui-CVE-2026-78677.json | 72 +++++++++++++ advisories/BREW-jiratui-CVE-2026-78678.json | 72 +++++++++++++ .../BREW-jiratui-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-jiratui-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-kimi-cli-CVE-2026-76221.json | 13 ++- advisories/BREW-kimi-cli-CVE-2026-76222.json | 13 ++- advisories/BREW-kimi-cli-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-kimi-cli-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-kimi-cli-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-kimi-cli-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-kimi-cli-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-kimi-cli-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-legit-CVE-2026-76221.json | 13 ++- advisories/BREW-legit-CVE-2026-76222.json | 13 ++- advisories/BREW-legit-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-legit-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-legit-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-legit-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-legit-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-legit-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-llm-CVE-2026-31236.json | 10 +- advisories/BREW-llm-CVE-2026-7246.json | 8 +- .../BREW-mailcatcher-CVE-2009-3287.json | 8 +- .../BREW-mailcatcher-CVE-2011-0739.json | 8 +- .../BREW-mailcatcher-CVE-2011-5036.json | 8 +- .../BREW-mailcatcher-CVE-2012-2139.json | 8 +- .../BREW-mailcatcher-CVE-2012-2140.json | 8 +- .../BREW-mailcatcher-CVE-2012-6109.json | 8 +- .../BREW-mailcatcher-CVE-2013-0183.json | 8 +- .../BREW-mailcatcher-CVE-2013-0184.json | 8 +- .../BREW-mailcatcher-CVE-2013-0262.json | 8 +- .../BREW-mailcatcher-CVE-2013-0263.json | 8 +- .../BREW-mailcatcher-CVE-2015-3225.json | 8 +- .../BREW-mailcatcher-CVE-2015-9097.json | 8 +- .../BREW-mailcatcher-CVE-2018-1000119.json | 8 +- .../BREW-mailcatcher-CVE-2018-11627.json | 8 +- .../BREW-mailcatcher-CVE-2018-16470.json | 8 +- .../BREW-mailcatcher-CVE-2018-16471.json | 8 +- .../BREW-mailcatcher-CVE-2018-7212.json | 8 +- .../BREW-mailcatcher-CVE-2019-16782.json | 8 +- .../BREW-mailcatcher-CVE-2020-15133.json | 8 +- .../BREW-mailcatcher-CVE-2020-8161.json | 8 +- .../BREW-mailcatcher-CVE-2020-8184.json | 8 +- .../BREW-mailcatcher-CVE-2021-41817.json | 8 +- .../BREW-mailcatcher-CVE-2022-29970.json | 8 +- .../BREW-mailcatcher-CVE-2022-30122.json | 8 +- .../BREW-mailcatcher-CVE-2022-30123.json | 8 +- .../BREW-mailcatcher-CVE-2022-44570.json | 10 +- .../BREW-mailcatcher-CVE-2022-44571.json | 10 +- .../BREW-mailcatcher-CVE-2022-44572.json | 10 +- .../BREW-mailcatcher-CVE-2022-45442.json | 8 +- .../BREW-mailcatcher-CVE-2023-27530.json | 10 +- .../BREW-mailcatcher-CVE-2023-27539.json | 10 +- .../BREW-mailcatcher-CVE-2024-21510.json | 15 +-- .../BREW-mailcatcher-CVE-2024-25126.json | 10 +- .../BREW-mailcatcher-CVE-2024-26141.json | 10 +- .../BREW-mailcatcher-CVE-2024-26146.json | 10 +- .../BREW-mailcatcher-CVE-2025-25184.json | 17 +-- .../BREW-mailcatcher-CVE-2025-25186.json | 17 +-- .../BREW-mailcatcher-CVE-2025-27111.json | 17 +-- .../BREW-mailcatcher-CVE-2025-27610.json | 17 +-- .../BREW-mailcatcher-CVE-2025-32441.json | 15 +-- .../BREW-mailcatcher-CVE-2025-43857.json | 17 +-- .../BREW-mailcatcher-CVE-2025-46727.json | 17 +-- .../BREW-mailcatcher-CVE-2025-59830.json | 15 +-- .../BREW-mailcatcher-CVE-2025-61770.json | 17 +-- .../BREW-mailcatcher-CVE-2025-61771.json | 17 +-- .../BREW-mailcatcher-CVE-2025-61772.json | 17 +-- .../BREW-mailcatcher-CVE-2025-61780.json | 17 +-- .../BREW-mailcatcher-CVE-2025-61919.json | 17 +-- .../BREW-mailcatcher-CVE-2025-61921.json | 15 +-- .../BREW-mailcatcher-CVE-2026-22860.json | 17 +-- .../BREW-mailcatcher-CVE-2026-25500.json | 17 +-- .../BREW-mailcatcher-CVE-2026-26961.json | 17 +-- .../BREW-mailcatcher-CVE-2026-34230.json | 17 +-- .../BREW-mailcatcher-CVE-2026-34763.json | 17 +-- .../BREW-mailcatcher-CVE-2026-34785.json | 17 +-- .../BREW-mailcatcher-CVE-2026-34786.json | 17 +-- .../BREW-mailcatcher-CVE-2026-34826.json | 17 +-- .../BREW-mailcatcher-CVE-2026-34829.json | 17 +-- .../BREW-mailcatcher-CVE-2026-34830.json | 17 +-- .../BREW-mailcatcher-CVE-2026-34831.json | 17 +-- .../BREW-mailcatcher-CVE-2026-42245.json | 17 +-- .../BREW-mailcatcher-CVE-2026-42246.json | 17 +-- .../BREW-mailcatcher-CVE-2026-42256.json | 17 +-- .../BREW-mailcatcher-CVE-2026-42257.json | 17 +-- .../BREW-mailcatcher-CVE-2026-42258.json | 17 +-- .../BREW-mailcatcher-CVE-2026-47240.json | 17 +-- .../BREW-mailcatcher-CVE-2026-47241.json | 17 +-- .../BREW-mailcatcher-CVE-2026-47242.json | 17 +-- .../BREW-mailcatcher-CVE-2026-54463.json | 15 +-- .../BREW-mailcatcher-CVE-2026-54464.json | 15 +-- .../BREW-mailcatcher-CVE-2026-54465.json | 15 +-- .../BREW-mailcatcher-CVE-2026-54619.json | 15 +-- .../BREW-mailcatcher-CVE-2026-61666.json | 15 +-- .../BREW-mailcatcher-CVE-2026-63435.json | 15 +-- .../BREW-mailcatcher-GHSA-mgvv-5mxp-xq67.json | 8 +- advisories/BREW-mentat-CVE-2026-76221.json | 13 ++- advisories/BREW-mentat-CVE-2026-76222.json | 13 ++- advisories/BREW-mentat-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-mentat-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-mentat-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-mentat-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-mentat-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-mentat-GHSA-jm78-9fvv-mhgr.json | 13 ++- .../BREW-mistral-vibe-CVE-2026-76221.json | 13 ++- .../BREW-mistral-vibe-CVE-2026-76222.json | 13 ++- .../BREW-mistral-vibe-CVE-2026-78675.json | 69 ++++++++++++ .../BREW-mistral-vibe-CVE-2026-78676.json | 69 ++++++++++++ .../BREW-mistral-vibe-CVE-2026-78677.json | 69 ++++++++++++ .../BREW-mistral-vibe-CVE-2026-78678.json | 69 ++++++++++++ ...BREW-mistral-vibe-GHSA-hmq2-w58f-27jc.json | 13 ++- ...BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-mk-CVE-2026-76221.json | 13 ++- advisories/BREW-mk-CVE-2026-76222.json | 13 ++- advisories/BREW-mk-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-mk-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-mk-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-mk-CVE-2026-78678.json | 69 ++++++++++++ advisories/BREW-mk-GHSA-hmq2-w58f-27jc.json | 13 ++- advisories/BREW-mk-GHSA-jm78-9fvv-mhgr.json | 13 ++- .../BREW-mkdocs-material-CVE-2026-73295.json | 100 +++++++++++++++++ advisories/BREW-mycli-CVE-2021-32839.json | 12 +-- advisories/BREW-mycli-CVE-2023-30608.json | 12 +-- advisories/BREW-mycli-CVE-2023-44690.json | 14 +-- advisories/BREW-mycli-CVE-2024-4340.json | 12 +-- advisories/BREW-mycli-CVE-2026-31236.json | 12 +-- advisories/BREW-mycli-CVE-2026-54284.json | 19 ++-- advisories/BREW-mycli-CVE-2026-59893.json | 19 ++-- advisories/BREW-mycli-CVE-2026-59894.json | 19 ++-- advisories/BREW-mycli-CVE-2026-71491.json | 19 ++-- advisories/BREW-mycli-CVE-2026-7246.json | 8 +- advisories/BREW-mycli-CVE-2026-84305.json | 15 +-- .../BREW-mycli-GHSA-27jp-wm6q-gp25.json | 8 +- advisories/BREW-n8n-mcp-CVE-2026-39974.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-41495.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-42282.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-42449.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-44694.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-45582.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-45707.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-54052.json | 6 +- advisories/BREW-n8n-mcp-CVE-2026-55608.json | 6 +- .../BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json | 6 +- .../BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json | 6 +- advisories/BREW-nbdime-CVE-2026-76221.json | 13 ++- advisories/BREW-nbdime-CVE-2026-76222.json | 13 ++- advisories/BREW-nbdime-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-nbdime-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-nbdime-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-nbdime-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-nbdime-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-nbdime-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-nx-CVE-2026-54753.json | 6 +- advisories/BREW-nx-CVE-2026-71476.json | 6 +- ...-opentimestamps-client-CVE-2026-76221.json | 13 ++- ...-opentimestamps-client-CVE-2026-76222.json | 13 ++- ...-opentimestamps-client-CVE-2026-78675.json | 69 ++++++++++++ ...-opentimestamps-client-CVE-2026-78676.json | 69 ++++++++++++ ...-opentimestamps-client-CVE-2026-78677.json | 69 ++++++++++++ ...-opentimestamps-client-CVE-2026-78678.json | 69 ++++++++++++ ...timestamps-client-GHSA-hmq2-w58f-27jc.json | 13 ++- ...timestamps-client-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-otterdog-CVE-2026-76221.json | 13 ++- advisories/BREW-otterdog-CVE-2026-76222.json | 13 ++- advisories/BREW-otterdog-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-otterdog-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-otterdog-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-otterdog-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-otterdog-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-otterdog-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-prowler-CVE-2015-5237.json | 12 +-- advisories/BREW-prowler-CVE-2016-6298.json | 12 +-- advisories/BREW-prowler-CVE-2021-22570.json | 8 +- advisories/BREW-prowler-CVE-2022-1941.json | 12 +-- advisories/BREW-prowler-CVE-2022-3102.json | 12 +-- advisories/BREW-prowler-CVE-2023-26145.json | 12 +-- advisories/BREW-prowler-CVE-2023-6681.json | 12 +-- advisories/BREW-prowler-CVE-2024-28102.json | 12 +-- advisories/BREW-prowler-CVE-2025-4565.json | 12 +-- advisories/BREW-prowler-CVE-2025-68146.json | 12 +-- advisories/BREW-prowler-CVE-2026-0994.json | 12 +-- advisories/BREW-prowler-CVE-2026-22701.json | 12 +-- advisories/BREW-prowler-CVE-2026-39373.json | 12 +-- advisories/BREW-pygitup-CVE-2026-76221.json | 13 ++- advisories/BREW-pygitup-CVE-2026-76222.json | 13 ++- advisories/BREW-pygitup-CVE-2026-78675.json | 72 +++++++++++++ advisories/BREW-pygitup-CVE-2026-78676.json | 72 +++++++++++++ advisories/BREW-pygitup-CVE-2026-78677.json | 72 +++++++++++++ advisories/BREW-pygitup-CVE-2026-78678.json | 72 +++++++++++++ .../BREW-pygitup-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-pygitup-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-renovate-CVE-2024-58376.json | 8 +- advisories/BREW-renovate-CVE-2026-76226.json | 8 +- advisories/BREW-renovate-CVE-2026-76227.json | 8 +- advisories/BREW-renovate-CVE-2026-76228.json | 8 +- advisories/BREW-renovate-CVE-2026-76229.json | 8 +- advisories/BREW-renovate-CVE-2026-76230.json | 8 +- advisories/BREW-renovate-CVE-2026-76231.json | 8 +- advisories/BREW-renovate-CVE-2026-76232.json | 8 +- advisories/BREW-renovate-CVE-2026-76233.json | 8 +- .../BREW-renovate-GHSA-36j9-mx87-2cff.json | 8 +- .../BREW-renovate-GHSA-36rh-ggpr-j3gj.json | 6 +- .../BREW-renovate-GHSA-3f44-xw83-3pmg.json | 8 +- .../BREW-renovate-GHSA-5vjq-5jmg-39xq.json | 8 +- .../BREW-renovate-GHSA-8wc6-vgrq-x6cf.json | 8 +- .../BREW-renovate-GHSA-fr4j-65pv-gjjj.json | 8 +- .../BREW-renovate-GHSA-pfq2-hh62-7m96.json | 8 +- .../BREW-renovate-GHSA-rqgv-292v-5qgr.json | 8 +- .../BREW-renovate-GHSA-v7x3-7hw7-pcjg.json | 6 +- .../BREW-renovate-GHSA-xjr7-3c3g-m763.json | 8 +- .../BREW-renovate-GHSA-xv56-3wq5-9997.json | 8 +- advisories/BREW-safety-CVE-2026-62384.json | 72 +++++++++++++ advisories/BREW-safety-CVE-2026-71514.json | 13 ++- .../BREW-shallow-backup-CVE-2026-76221.json | 13 ++- .../BREW-shallow-backup-CVE-2026-76222.json | 13 ++- .../BREW-shallow-backup-CVE-2026-78675.json | 69 ++++++++++++ .../BREW-shallow-backup-CVE-2026-78676.json | 69 ++++++++++++ .../BREW-shallow-backup-CVE-2026-78677.json | 69 ++++++++++++ .../BREW-shallow-backup-CVE-2026-78678.json | 69 ++++++++++++ ...EW-shallow-backup-GHSA-hmq2-w58f-27jc.json | 13 ++- ...EW-shallow-backup-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-snakemake-CVE-2026-76221.json | 13 ++- advisories/BREW-snakemake-CVE-2026-76222.json | 13 ++- advisories/BREW-snakemake-CVE-2026-78675.json | 72 +++++++++++++ advisories/BREW-snakemake-CVE-2026-78676.json | 72 +++++++++++++ advisories/BREW-snakemake-CVE-2026-78677.json | 72 +++++++++++++ advisories/BREW-snakemake-CVE-2026-78678.json | 72 +++++++++++++ .../BREW-snakemake-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-snakemake-GHSA-jm78-9fvv-mhgr.json | 13 ++- .../BREW-snowflake-cli-CVE-2026-76221.json | 13 ++- .../BREW-snowflake-cli-CVE-2026-76222.json | 13 ++- .../BREW-snowflake-cli-CVE-2026-78675.json | 69 ++++++++++++ .../BREW-snowflake-cli-CVE-2026-78676.json | 69 ++++++++++++ .../BREW-snowflake-cli-CVE-2026-78677.json | 69 ++++++++++++ .../BREW-snowflake-cli-CVE-2026-78678.json | 69 ++++++++++++ ...REW-snowflake-cli-GHSA-hmq2-w58f-27jc.json | 13 ++- ...REW-snowflake-cli-GHSA-jm78-9fvv-mhgr.json | 13 ++- .../BREW-standardebooks-CVE-2026-76221.json | 13 ++- .../BREW-standardebooks-CVE-2026-76222.json | 13 ++- .../BREW-standardebooks-CVE-2026-78675.json | 69 ++++++++++++ .../BREW-standardebooks-CVE-2026-78676.json | 69 ++++++++++++ .../BREW-standardebooks-CVE-2026-78677.json | 69 ++++++++++++ .../BREW-standardebooks-CVE-2026-78678.json | 69 ++++++++++++ ...EW-standardebooks-GHSA-hmq2-w58f-27jc.json | 13 ++- ...EW-standardebooks-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-tach-CVE-2026-76221.json | 13 ++- advisories/BREW-tach-CVE-2026-76222.json | 13 ++- advisories/BREW-tach-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-tach-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-tach-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-tach-CVE-2026-78678.json | 69 ++++++++++++ advisories/BREW-tach-GHSA-hmq2-w58f-27jc.json | 13 ++- advisories/BREW-tach-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-tartufo-CVE-2026-76221.json | 13 ++- advisories/BREW-tartufo-CVE-2026-76222.json | 13 ++- advisories/BREW-tartufo-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-tartufo-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-tartufo-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-tartufo-CVE-2026-78678.json | 69 ++++++++++++ .../BREW-tartufo-GHSA-hmq2-w58f-27jc.json | 13 ++- .../BREW-tartufo-GHSA-jm78-9fvv-mhgr.json | 13 ++- advisories/BREW-tern-CVE-2026-76221.json | 13 ++- advisories/BREW-tern-CVE-2026-76222.json | 13 ++- advisories/BREW-tern-CVE-2026-78675.json | 69 ++++++++++++ advisories/BREW-tern-CVE-2026-78676.json | 69 ++++++++++++ advisories/BREW-tern-CVE-2026-78677.json | 69 ++++++++++++ advisories/BREW-tern-CVE-2026-78678.json | 69 ++++++++++++ advisories/BREW-tern-GHSA-hmq2-w58f-27jc.json | 13 ++- advisories/BREW-tern-GHSA-jm78-9fvv-mhgr.json | 13 ++- 405 files changed, 11232 insertions(+), 1034 deletions(-) create mode 100644 advisories/BREW-acronym-CVE-2026-62384.json create mode 100644 advisories/BREW-aider-CVE-2026-78675.json create mode 100644 advisories/BREW-aider-CVE-2026-78676.json create mode 100644 advisories/BREW-aider-CVE-2026-78677.json create mode 100644 advisories/BREW-aider-CVE-2026-78678.json create mode 100644 advisories/BREW-apm-CVE-2026-78675.json create mode 100644 advisories/BREW-apm-CVE-2026-78676.json create mode 100644 advisories/BREW-apm-CVE-2026-78677.json create mode 100644 advisories/BREW-apm-CVE-2026-78678.json create mode 100644 advisories/BREW-btcli-CVE-2026-78675.json create mode 100644 advisories/BREW-btcli-CVE-2026-78676.json create mode 100644 advisories/BREW-btcli-CVE-2026-78677.json create mode 100644 advisories/BREW-btcli-CVE-2026-78678.json create mode 100644 advisories/BREW-cf2tf-CVE-2026-78675.json create mode 100644 advisories/BREW-cf2tf-CVE-2026-78676.json create mode 100644 advisories/BREW-cf2tf-CVE-2026-78677.json create mode 100644 advisories/BREW-cf2tf-CVE-2026-78678.json create mode 100644 advisories/BREW-checkov-CVE-2026-78675.json create mode 100644 advisories/BREW-checkov-CVE-2026-78676.json create mode 100644 advisories/BREW-checkov-CVE-2026-78677.json create mode 100644 advisories/BREW-checkov-CVE-2026-78678.json create mode 100644 advisories/BREW-claude-code-templates-CVE-2026-73222.json create mode 100644 advisories/BREW-cobo-cli-CVE-2026-78675.json create mode 100644 advisories/BREW-cobo-cli-CVE-2026-78676.json create mode 100644 advisories/BREW-cobo-cli-CVE-2026-78677.json create mode 100644 advisories/BREW-cobo-cli-CVE-2026-78678.json create mode 100644 advisories/BREW-conda-lock-CVE-2026-78675.json create mode 100644 advisories/BREW-conda-lock-CVE-2026-78676.json create mode 100644 advisories/BREW-conda-lock-CVE-2026-78677.json create mode 100644 advisories/BREW-conda-lock-CVE-2026-78678.json create mode 100644 advisories/BREW-cruft-CVE-2026-78675.json create mode 100644 advisories/BREW-cruft-CVE-2026-78676.json create mode 100644 advisories/BREW-cruft-CVE-2026-78677.json create mode 100644 advisories/BREW-cruft-CVE-2026-78678.json create mode 100644 advisories/BREW-cycode-CVE-2026-78675.json create mode 100644 advisories/BREW-cycode-CVE-2026-78676.json create mode 100644 advisories/BREW-cycode-CVE-2026-78677.json create mode 100644 advisories/BREW-cycode-CVE-2026-78678.json create mode 100644 advisories/BREW-dstack-CVE-2026-78675.json create mode 100644 advisories/BREW-dstack-CVE-2026-78676.json create mode 100644 advisories/BREW-dstack-CVE-2026-78677.json create mode 100644 advisories/BREW-dstack-CVE-2026-78678.json create mode 100644 advisories/BREW-dvc-CVE-2026-78675.json create mode 100644 advisories/BREW-dvc-CVE-2026-78676.json create mode 100644 advisories/BREW-dvc-CVE-2026-78677.json create mode 100644 advisories/BREW-dvc-CVE-2026-78678.json create mode 100644 advisories/BREW-esptool-CVE-2018-1000518.json create mode 100644 advisories/BREW-esptool-CVE-2021-33880.json create mode 100644 advisories/BREW-fdroidserver-CVE-2026-78675.json create mode 100644 advisories/BREW-fdroidserver-CVE-2026-78676.json create mode 100644 advisories/BREW-fdroidserver-CVE-2026-78677.json create mode 100644 advisories/BREW-fdroidserver-CVE-2026-78678.json create mode 100644 advisories/BREW-gitup-CVE-2026-78675.json create mode 100644 advisories/BREW-gitup-CVE-2026-78676.json create mode 100644 advisories/BREW-gitup-CVE-2026-78677.json create mode 100644 advisories/BREW-gitup-CVE-2026-78678.json create mode 100644 advisories/BREW-gptline-CVE-2026-62384.json create mode 100644 advisories/BREW-jiratui-CVE-2026-78675.json create mode 100644 advisories/BREW-jiratui-CVE-2026-78676.json create mode 100644 advisories/BREW-jiratui-CVE-2026-78677.json create mode 100644 advisories/BREW-jiratui-CVE-2026-78678.json create mode 100644 advisories/BREW-kimi-cli-CVE-2026-78675.json create mode 100644 advisories/BREW-kimi-cli-CVE-2026-78676.json create mode 100644 advisories/BREW-kimi-cli-CVE-2026-78677.json create mode 100644 advisories/BREW-kimi-cli-CVE-2026-78678.json create mode 100644 advisories/BREW-legit-CVE-2026-78675.json create mode 100644 advisories/BREW-legit-CVE-2026-78676.json create mode 100644 advisories/BREW-legit-CVE-2026-78677.json create mode 100644 advisories/BREW-legit-CVE-2026-78678.json create mode 100644 advisories/BREW-mentat-CVE-2026-78675.json create mode 100644 advisories/BREW-mentat-CVE-2026-78676.json create mode 100644 advisories/BREW-mentat-CVE-2026-78677.json create mode 100644 advisories/BREW-mentat-CVE-2026-78678.json create mode 100644 advisories/BREW-mistral-vibe-CVE-2026-78675.json create mode 100644 advisories/BREW-mistral-vibe-CVE-2026-78676.json create mode 100644 advisories/BREW-mistral-vibe-CVE-2026-78677.json create mode 100644 advisories/BREW-mistral-vibe-CVE-2026-78678.json create mode 100644 advisories/BREW-mk-CVE-2026-78675.json create mode 100644 advisories/BREW-mk-CVE-2026-78676.json create mode 100644 advisories/BREW-mk-CVE-2026-78677.json create mode 100644 advisories/BREW-mk-CVE-2026-78678.json create mode 100644 advisories/BREW-mkdocs-material-CVE-2026-73295.json create mode 100644 advisories/BREW-nbdime-CVE-2026-78675.json create mode 100644 advisories/BREW-nbdime-CVE-2026-78676.json create mode 100644 advisories/BREW-nbdime-CVE-2026-78677.json create mode 100644 advisories/BREW-nbdime-CVE-2026-78678.json create mode 100644 advisories/BREW-opentimestamps-client-CVE-2026-78675.json create mode 100644 advisories/BREW-opentimestamps-client-CVE-2026-78676.json create mode 100644 advisories/BREW-opentimestamps-client-CVE-2026-78677.json create mode 100644 advisories/BREW-opentimestamps-client-CVE-2026-78678.json create mode 100644 advisories/BREW-otterdog-CVE-2026-78675.json create mode 100644 advisories/BREW-otterdog-CVE-2026-78676.json create mode 100644 advisories/BREW-otterdog-CVE-2026-78677.json create mode 100644 advisories/BREW-otterdog-CVE-2026-78678.json create mode 100644 advisories/BREW-pygitup-CVE-2026-78675.json create mode 100644 advisories/BREW-pygitup-CVE-2026-78676.json create mode 100644 advisories/BREW-pygitup-CVE-2026-78677.json create mode 100644 advisories/BREW-pygitup-CVE-2026-78678.json create mode 100644 advisories/BREW-safety-CVE-2026-62384.json create mode 100644 advisories/BREW-shallow-backup-CVE-2026-78675.json create mode 100644 advisories/BREW-shallow-backup-CVE-2026-78676.json create mode 100644 advisories/BREW-shallow-backup-CVE-2026-78677.json create mode 100644 advisories/BREW-shallow-backup-CVE-2026-78678.json create mode 100644 advisories/BREW-snakemake-CVE-2026-78675.json create mode 100644 advisories/BREW-snakemake-CVE-2026-78676.json create mode 100644 advisories/BREW-snakemake-CVE-2026-78677.json create mode 100644 advisories/BREW-snakemake-CVE-2026-78678.json create mode 100644 advisories/BREW-snowflake-cli-CVE-2026-78675.json create mode 100644 advisories/BREW-snowflake-cli-CVE-2026-78676.json create mode 100644 advisories/BREW-snowflake-cli-CVE-2026-78677.json create mode 100644 advisories/BREW-snowflake-cli-CVE-2026-78678.json create mode 100644 advisories/BREW-standardebooks-CVE-2026-78675.json create mode 100644 advisories/BREW-standardebooks-CVE-2026-78676.json create mode 100644 advisories/BREW-standardebooks-CVE-2026-78677.json create mode 100644 advisories/BREW-standardebooks-CVE-2026-78678.json create mode 100644 advisories/BREW-tach-CVE-2026-78675.json create mode 100644 advisories/BREW-tach-CVE-2026-78676.json create mode 100644 advisories/BREW-tach-CVE-2026-78677.json create mode 100644 advisories/BREW-tach-CVE-2026-78678.json create mode 100644 advisories/BREW-tartufo-CVE-2026-78675.json create mode 100644 advisories/BREW-tartufo-CVE-2026-78676.json create mode 100644 advisories/BREW-tartufo-CVE-2026-78677.json create mode 100644 advisories/BREW-tartufo-CVE-2026-78678.json create mode 100644 advisories/BREW-tern-CVE-2026-78675.json create mode 100644 advisories/BREW-tern-CVE-2026-78676.json create mode 100644 advisories/BREW-tern-CVE-2026-78677.json create mode 100644 advisories/BREW-tern-CVE-2026-78678.json diff --git a/advisories/BREW-acronym-CVE-2026-62384.json b/advisories/BREW-acronym-CVE-2026-62384.json new file mode 100644 index 00000000000..c5214d94d85 --- /dev/null +++ b/advisories/BREW-acronym-CVE-2026-62384.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-acronym-CVE-2026-62384", + "published": "2026-09-04T08:43:15Z", + "modified": "2026-09-04T08:43:15Z", + "upstream": [ + "PYSEC-2026-3789", + "CVE-2026-62384", + "GHSA-f833-7jw8-xwrv" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "acronym", + "purl": "pkg:brew/acronym" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.0.0_5" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.10.2", + "resource": "nltk", + "resource_purl": "pkg:pypi/nltk@3.10.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + } + ] + }, + "details": "NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/nltk-framenetcorpusreader-symlink-sandbox-bypass-before" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv" + } + ] +} diff --git a/advisories/BREW-acronym-CVE-2026-71514.json b/advisories/BREW-acronym-CVE-2026-71514.json index a2361becfa9..dd69c3fc4bf 100644 --- a/advisories/BREW-acronym-CVE-2026-71514.json +++ b/advisories/BREW-acronym-CVE-2026-71514.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-acronym-CVE-2026-71514", "published": "2026-09-03T08:45:00Z", - "modified": "2026-09-03T08:45:00Z", + "modified": "2026-09-04T08:42:59Z", "upstream": [ "GHSA-cv22-g7mw-8v73", - "CVE-2026-71514" + "CVE-2026-71514", + "PYSEC-2026-3790" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aider-CVE-2026-76221.json b/advisories/BREW-aider-CVE-2026-76221.json index c51ddddddeb..30ab7346dcb 100644 --- a/advisories/BREW-aider-CVE-2026-76221.json +++ b/advisories/BREW-aider-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-aider-CVE-2026-76221", "published": "2026-08-20T08:39:09Z", - "modified": "2026-08-20T08:39:09Z", + "modified": "2026-09-04T08:43:32Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aider-CVE-2026-76222.json b/advisories/BREW-aider-CVE-2026-76222.json index e38331819ed..4e9e92620b1 100644 --- a/advisories/BREW-aider-CVE-2026-76222.json +++ b/advisories/BREW-aider-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-aider-CVE-2026-76222", "published": "2026-08-20T08:39:09Z", - "modified": "2026-08-20T08:39:09Z", + "modified": "2026-09-04T08:43:32Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aider-CVE-2026-78675.json b/advisories/BREW-aider-CVE-2026-78675.json new file mode 100644 index 00000000000..698cedfef4c --- /dev/null +++ b/advisories/BREW-aider-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-aider-CVE-2026-78675", + "published": "2026-09-04T08:43:32Z", + "modified": "2026-09-04T08:43:32Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "aider", + "purl": "pkg:brew/aider" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.46" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-aider-CVE-2026-78676.json b/advisories/BREW-aider-CVE-2026-78676.json new file mode 100644 index 00000000000..20930f558b7 --- /dev/null +++ b/advisories/BREW-aider-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-aider-CVE-2026-78676", + "published": "2026-09-04T08:43:32Z", + "modified": "2026-09-04T08:43:32Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "aider", + "purl": "pkg:brew/aider" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.46" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-aider-CVE-2026-78677.json b/advisories/BREW-aider-CVE-2026-78677.json new file mode 100644 index 00000000000..e447ef9abe0 --- /dev/null +++ b/advisories/BREW-aider-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-aider-CVE-2026-78677", + "published": "2026-09-04T08:43:32Z", + "modified": "2026-09-04T08:43:32Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "aider", + "purl": "pkg:brew/aider" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.46" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-aider-CVE-2026-78678.json b/advisories/BREW-aider-CVE-2026-78678.json new file mode 100644 index 00000000000..8d12ebe21e7 --- /dev/null +++ b/advisories/BREW-aider-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-aider-CVE-2026-78678", + "published": "2026-09-04T08:43:32Z", + "modified": "2026-09-04T08:43:32Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "aider", + "purl": "pkg:brew/aider" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.46" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-aider-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-aider-GHSA-hmq2-w58f-27jc.json index b1206459b7c..5be494f8860 100644 --- a/advisories/BREW-aider-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-aider-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-aider-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:35:12Z", - "modified": "2026-08-29T08:37:49Z", + "modified": "2026-09-04T08:43:32Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-aider-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-aider-GHSA-jm78-9fvv-mhgr.json index df2d0256e7b..9364bb99b2f 100644 --- a/advisories/BREW-aider-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-aider-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-aider-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:35:12Z", - "modified": "2026-08-29T08:37:49Z", + "modified": "2026-09-04T08:43:32Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.46", + "key": "pkg:pypi/gitpython@3.1.46", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-allure-CVE-2026-55846.json b/advisories/BREW-allure-CVE-2026-55846.json index 84ffbefda08..7aff386d3ec 100644 --- a/advisories/BREW-allure-CVE-2026-55846.json +++ b/advisories/BREW-allure-CVE-2026-55846.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-allure-CVE-2026-55846", "published": "2026-08-13T16:35:13Z", - "modified": "2026-08-28T12:17:10Z", + "modified": "2026-09-04T08:43:33Z", "upstream": [ "GHSA-82cg-3hv7-74gc", "CVE-2026-55846" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "Maven", "name": "io.qameta.allure:allure-commandline", - "subject_version": "2.46.0", - "key": "pkg:maven/io.qameta.allure/allure-commandline@2.46.0" + "subject_version": "2.46.1", + "key": "pkg:maven/io.qameta.allure/allure-commandline@2.46.1" } ] }, diff --git a/advisories/BREW-apm-CVE-2026-76221.json b/advisories/BREW-apm-CVE-2026-76221.json index 88f4818c51a..84d394c18a3 100644 --- a/advisories/BREW-apm-CVE-2026-76221.json +++ b/advisories/BREW-apm-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-76221", "published": "2026-08-20T08:39:48Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-04T08:44:14Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-76222.json b/advisories/BREW-apm-CVE-2026-76222.json index a9509dfae94..3bbb7556553 100644 --- a/advisories/BREW-apm-CVE-2026-76222.json +++ b/advisories/BREW-apm-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-CVE-2026-76222", "published": "2026-08-20T08:39:48Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-04T08:44:14Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-CVE-2026-78675.json b/advisories/BREW-apm-CVE-2026-78675.json new file mode 100644 index 00000000000..51bd38b8abe --- /dev/null +++ b/advisories/BREW-apm-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-apm-CVE-2026-78675", + "published": "2026-09-04T08:44:32Z", + "modified": "2026-09-04T08:44:32Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "apm", + "purl": "pkg:brew/apm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.29.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-apm-CVE-2026-78676.json b/advisories/BREW-apm-CVE-2026-78676.json new file mode 100644 index 00000000000..4221ddd6ef2 --- /dev/null +++ b/advisories/BREW-apm-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-apm-CVE-2026-78676", + "published": "2026-09-04T08:44:32Z", + "modified": "2026-09-04T08:44:32Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "apm", + "purl": "pkg:brew/apm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.29.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-apm-CVE-2026-78677.json b/advisories/BREW-apm-CVE-2026-78677.json new file mode 100644 index 00000000000..a5e72b1e38c --- /dev/null +++ b/advisories/BREW-apm-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-apm-CVE-2026-78677", + "published": "2026-09-04T08:44:32Z", + "modified": "2026-09-04T08:44:32Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "apm", + "purl": "pkg:brew/apm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.29.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-apm-CVE-2026-78678.json b/advisories/BREW-apm-CVE-2026-78678.json new file mode 100644 index 00000000000..38a0ee32389 --- /dev/null +++ b/advisories/BREW-apm-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-apm-CVE-2026-78678", + "published": "2026-09-04T08:44:32Z", + "modified": "2026-09-04T08:44:32Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "apm", + "purl": "pkg:brew/apm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.29.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-apm-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-apm-GHSA-hmq2-w58f-27jc.json index 1b14aee5975..570782f031b 100644 --- a/advisories/BREW-apm-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-apm-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-04T08:44:14Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-apm-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-apm-GHSA-jm78-9fvv-mhgr.json index a3c6f1e965f..b50182f82fc 100644 --- a/advisories/BREW-apm-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-apm-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-apm-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:35:55Z", - "modified": "2026-09-02T08:44:40Z", + "modified": "2026-09-04T08:44:14Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-btcli-CVE-2026-76221.json b/advisories/BREW-btcli-CVE-2026-76221.json index 23374ec8e7a..bb398f8153a 100644 --- a/advisories/BREW-btcli-CVE-2026-76221.json +++ b/advisories/BREW-btcli-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-btcli-CVE-2026-76221", "published": "2026-08-20T08:42:00Z", - "modified": "2026-08-20T08:42:00Z", + "modified": "2026-09-04T08:47:49Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-btcli-CVE-2026-76222.json b/advisories/BREW-btcli-CVE-2026-76222.json index 6be2482023f..f8af73204e3 100644 --- a/advisories/BREW-btcli-CVE-2026-76222.json +++ b/advisories/BREW-btcli-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-btcli-CVE-2026-76222", "published": "2026-08-20T08:42:00Z", - "modified": "2026-08-20T08:42:00Z", + "modified": "2026-09-04T08:47:49Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-btcli-CVE-2026-78675.json b/advisories/BREW-btcli-CVE-2026-78675.json new file mode 100644 index 00000000000..58e0a99aac6 --- /dev/null +++ b/advisories/BREW-btcli-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-btcli-CVE-2026-78675", + "published": "2026-09-04T08:47:49Z", + "modified": "2026-09-04T08:47:49Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "btcli", + "purl": "pkg:brew/btcli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.51" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-btcli-CVE-2026-78676.json b/advisories/BREW-btcli-CVE-2026-78676.json new file mode 100644 index 00000000000..2d3f9c166ac --- /dev/null +++ b/advisories/BREW-btcli-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-btcli-CVE-2026-78676", + "published": "2026-09-04T08:47:49Z", + "modified": "2026-09-04T08:47:49Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "btcli", + "purl": "pkg:brew/btcli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.51" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-btcli-CVE-2026-78677.json b/advisories/BREW-btcli-CVE-2026-78677.json new file mode 100644 index 00000000000..c93f455d535 --- /dev/null +++ b/advisories/BREW-btcli-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-btcli-CVE-2026-78677", + "published": "2026-09-04T08:47:49Z", + "modified": "2026-09-04T08:47:49Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "btcli", + "purl": "pkg:brew/btcli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.51" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-btcli-CVE-2026-78678.json b/advisories/BREW-btcli-CVE-2026-78678.json new file mode 100644 index 00000000000..13ed904e903 --- /dev/null +++ b/advisories/BREW-btcli-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-btcli-CVE-2026-78678", + "published": "2026-09-04T08:47:49Z", + "modified": "2026-09-04T08:47:49Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "btcli", + "purl": "pkg:brew/btcli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.51" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-btcli-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-btcli-GHSA-hmq2-w58f-27jc.json index ffd362dcfd8..6cc1fde4378 100644 --- a/advisories/BREW-btcli-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-btcli-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-btcli-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-29T08:41:30Z", + "modified": "2026-09-04T08:47:49Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-btcli-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-btcli-GHSA-jm78-9fvv-mhgr.json index 8dbad76d320..16de6c81240 100644 --- a/advisories/BREW-btcli-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-btcli-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-btcli-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:38:25Z", - "modified": "2026-08-29T08:41:30Z", + "modified": "2026-09-04T08:47:49Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.51", + "key": "pkg:pypi/gitpython@3.1.51", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cf2tf-CVE-2026-76221.json b/advisories/BREW-cf2tf-CVE-2026-76221.json index e2f7c7041e8..0be2b289c6b 100644 --- a/advisories/BREW-cf2tf-CVE-2026-76221.json +++ b/advisories/BREW-cf2tf-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cf2tf-CVE-2026-76221", "published": "2026-08-20T08:42:33Z", - "modified": "2026-08-20T08:42:33Z", + "modified": "2026-09-04T08:48:55Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cf2tf-CVE-2026-76222.json b/advisories/BREW-cf2tf-CVE-2026-76222.json index f8f23bf85cd..0eb90994c40 100644 --- a/advisories/BREW-cf2tf-CVE-2026-76222.json +++ b/advisories/BREW-cf2tf-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cf2tf-CVE-2026-76222", "published": "2026-08-20T08:42:33Z", - "modified": "2026-08-20T08:42:33Z", + "modified": "2026-09-04T08:48:55Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cf2tf-CVE-2026-78675.json b/advisories/BREW-cf2tf-CVE-2026-78675.json new file mode 100644 index 00000000000..c411f1b9077 --- /dev/null +++ b/advisories/BREW-cf2tf-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cf2tf-CVE-2026-78675", + "published": "2026-09-04T08:48:55Z", + "modified": "2026-09-04T08:48:55Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cf2tf", + "purl": "pkg:brew/cf2tf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-cf2tf-CVE-2026-78676.json b/advisories/BREW-cf2tf-CVE-2026-78676.json new file mode 100644 index 00000000000..1085ce0ef2d --- /dev/null +++ b/advisories/BREW-cf2tf-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cf2tf-CVE-2026-78676", + "published": "2026-09-04T08:48:55Z", + "modified": "2026-09-04T08:48:55Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cf2tf", + "purl": "pkg:brew/cf2tf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-cf2tf-CVE-2026-78677.json b/advisories/BREW-cf2tf-CVE-2026-78677.json new file mode 100644 index 00000000000..af5ff5eff01 --- /dev/null +++ b/advisories/BREW-cf2tf-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cf2tf-CVE-2026-78677", + "published": "2026-09-04T08:48:55Z", + "modified": "2026-09-04T08:48:55Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cf2tf", + "purl": "pkg:brew/cf2tf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-cf2tf-CVE-2026-78678.json b/advisories/BREW-cf2tf-CVE-2026-78678.json new file mode 100644 index 00000000000..5bd65b1016e --- /dev/null +++ b/advisories/BREW-cf2tf-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cf2tf-CVE-2026-78678", + "published": "2026-09-04T08:48:55Z", + "modified": "2026-09-04T08:48:55Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cf2tf", + "purl": "pkg:brew/cf2tf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-cf2tf-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-cf2tf-GHSA-hmq2-w58f-27jc.json index 3ea1c2c2667..546b6644e36 100644 --- a/advisories/BREW-cf2tf-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-cf2tf-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cf2tf-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-29T08:42:08Z", + "modified": "2026-09-04T08:48:55Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cf2tf-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-cf2tf-GHSA-jm78-9fvv-mhgr.json index f75e3acc9b9..347956bd77f 100644 --- a/advisories/BREW-cf2tf-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-cf2tf-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cf2tf-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:39:03Z", - "modified": "2026-08-29T08:42:08Z", + "modified": "2026-09-04T08:48:55Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-checkov-CVE-2026-76221.json b/advisories/BREW-checkov-CVE-2026-76221.json index 3c9e7084654..3900c9ed199 100644 --- a/advisories/BREW-checkov-CVE-2026-76221.json +++ b/advisories/BREW-checkov-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-checkov-CVE-2026-76221", "published": "2026-08-20T08:43:02Z", - "modified": "2026-08-20T08:43:02Z", + "modified": "2026-09-04T08:50:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-checkov-CVE-2026-76222.json b/advisories/BREW-checkov-CVE-2026-76222.json index 4ff41f619b1..8b82fb56764 100644 --- a/advisories/BREW-checkov-CVE-2026-76222.json +++ b/advisories/BREW-checkov-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-checkov-CVE-2026-76222", "published": "2026-08-20T08:43:02Z", - "modified": "2026-08-20T08:43:02Z", + "modified": "2026-09-04T08:50:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-checkov-CVE-2026-78675.json b/advisories/BREW-checkov-CVE-2026-78675.json new file mode 100644 index 00000000000..ebdf2904248 --- /dev/null +++ b/advisories/BREW-checkov-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-checkov-CVE-2026-78675", + "published": "2026-09-04T08:50:22Z", + "modified": "2026-09-04T08:50:22Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "checkov", + "purl": "pkg:brew/checkov" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.3.10" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-checkov-CVE-2026-78676.json b/advisories/BREW-checkov-CVE-2026-78676.json new file mode 100644 index 00000000000..80236f837d7 --- /dev/null +++ b/advisories/BREW-checkov-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-checkov-CVE-2026-78676", + "published": "2026-09-04T08:50:22Z", + "modified": "2026-09-04T08:50:22Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "checkov", + "purl": "pkg:brew/checkov" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.3.10" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-checkov-CVE-2026-78677.json b/advisories/BREW-checkov-CVE-2026-78677.json new file mode 100644 index 00000000000..189f8e63d37 --- /dev/null +++ b/advisories/BREW-checkov-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-checkov-CVE-2026-78677", + "published": "2026-09-04T08:50:22Z", + "modified": "2026-09-04T08:50:22Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "checkov", + "purl": "pkg:brew/checkov" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.3.10" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-checkov-CVE-2026-78678.json b/advisories/BREW-checkov-CVE-2026-78678.json new file mode 100644 index 00000000000..cc6a5b1ffda --- /dev/null +++ b/advisories/BREW-checkov-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-checkov-CVE-2026-78678", + "published": "2026-09-04T08:50:22Z", + "modified": "2026-09-04T08:50:22Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "checkov", + "purl": "pkg:brew/checkov" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.3.10" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-checkov-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-checkov-GHSA-hmq2-w58f-27jc.json index a5a9815a9d4..0bdc3a84030 100644 --- a/advisories/BREW-checkov-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-checkov-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-checkov-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:39:32Z", - "modified": "2026-08-29T08:42:40Z", + "modified": "2026-09-04T08:50:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-checkov-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-checkov-GHSA-jm78-9fvv-mhgr.json index f3d21283d5f..b254944beb5 100644 --- a/advisories/BREW-checkov-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-checkov-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-checkov-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:39:32Z", - "modified": "2026-08-29T08:42:40Z", + "modified": "2026-09-04T08:50:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-claude-code-templates-CVE-2026-73222.json b/advisories/BREW-claude-code-templates-CVE-2026-73222.json new file mode 100644 index 00000000000..a736d9bf779 --- /dev/null +++ b/advisories/BREW-claude-code-templates-CVE-2026-73222.json @@ -0,0 +1,81 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-claude-code-templates-CVE-2026-73222", + "published": "2026-09-04T08:51:25Z", + "modified": "2026-09-04T08:51:25Z", + "upstream": [ + "GHSA-79wm-x847-7cvg", + "CVE-2026-73222" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "claude-code-templates", + "purl": "pkg:brew/claude-code-templates" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.29.4" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "1.29.4" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "npm", + "name": "claude-code-templates", + "subject_version": "1.29.4", + "key": "pkg:npm/claude-code-templates@1.29.4" + } + ] + }, + "summary": "Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)", + "details": "### Summary\n`npx claude-code-templates --studio` launches \"Claude Code Studio\", an Express HTTP server (`cli-tool/src/sandbox-server.js`, default port 3444) that binds to **all interfaces** (`0.0.0.0`), sets `Access-Control-Allow-Origin: *`, and requires **no authentication**. Two POST endpoints pass attacker-controlled request-body fields into `child_process.spawn(..., { shell: true })`. Because `shell: true` makes Node join the argv array into a single `sh -c` string, the fields are parsed by the shell and metacharacters execute. Any unauthenticated attacker who can reach the port — a malicious web page the developer visits, or anyone on the same LAN — can execute arbitrary OS commands on the developer's machine.\n\n### Details\nIn `cli-tool/src/sandbox-server.js`:\n\n- `app.listen(PORT, ...)` is called with no host argument, so the server listens on `0.0.0.0` / `::` (reachable from the LAN, not just localhost).\n- The CORS middleware sends `Access-Control-Allow-Origin: *` and answers the preflight `OPTIONS` for any origin, so a browser will deliver cross-origin POSTs to it.\n- There is no authentication on any endpoint.\n\nThe vulnerable sinks:\n\n1. `POST /api/execute` — the `prompt` body field flows into `executeLocalTask()`:\n ```js\n const child = spawn('claude', [finalPrompt], { /* ... */ shell: true });\n The only validation on prompt is a length check (>= 10 chars). With shell: true, finalPrompt is interpreted by the shell.\n\n2. POST /api/install-agent — the agentName body field:\nconst child = spawn('npx', ['claude-code-templates@latest', '--agent', agentName, '--yes'], { /* ... */ shell: true });\n2. agentName is used unvalidated. (The same unsafe pattern is also reachable through /api/execute's agent field via checkAndInstallAgent().)\n\nRoot cause: spawn(cmd, argsArray, { shell: true }) does not keep argsArray as separate argv entries — Node builds cmd + ' ' + argsArray.join(' ') and runs it via sh -c, so every element is subject to shell parsing.\n\nPoC\n\n# Victim\nnpx claude-code-templates --studio # server on 0.0.0.0:3444\n\n# Attacker (another LAN host, or a malicious web page fetch(), or locally)\ncurl -s -X POST http://127.0.0.1:3444/api/execute \\\n -H 'Content-Type: application/json' \\\n --data '{\"prompt\":\"aaaaaaaaaa; touch /tmp/CCT_RCE_PROOF\",\"mode\":\"local\"}'\n\ncurl -s -X POST http://127.0.0.1:3444/api/install-agent \\\n -H 'Content-Type: application/json' \\\n --data '{\"agentName\":\"x; touch /tmp/CCT_AGENT_PROOF #\"}'\n\nls -la /tmp/CCT_RCE_PROOF /tmp/CCT_AGENT_PROOF # both created => injected commands ran\nThe aaaaaaaaaa padding satisfies the 10-char minimum, then ; (or $(...), or backticks) starts the injected command. claude/npx do not even need to be installed — the injected segment runs regardless.\n\nConfirmed at runtime on v1.28.13 (Node 22, Linux): both marker files were created, the server listened on *:3444, and an OPTIONS preflight from Origin: https://evil.example returned 200 with Access-Control-Allow-Origin: *.\n\nImpact\n\nUnauthenticated remote code execution (CWE-78) on any machine running --studio. Two reachability paths:\n- Drive-by: a developer running --studio who visits an attacker-controlled web page — the page's cross-origin fetch() (Content-Type application/json) passes the wildcard CORS preflight and delivers the POST, achieving RCE with no other interaction.\n- LAN: because the server binds 0.0.0.0, anyone on the same network (office, co-working space, public Wi-Fi) can hit port 3444 directly.\n\nImpact is full compromise of the developer's user account (arbitrary command execution with the developer's privileges): source code, SSH keys, cloud credentials, and .env secrets.\n\nSuggested fix\n\n- Remove shell: true from all three spawns so arguments stay discrete argv entries (kills the injection).\n- Validate agentName against a strict allowlist (^[A-Za-z0-9._/-]+$).\n- Bind to loopback only (app.listen(PORT, '127.0.0.1', ...)).\n- Replace the wildcard CORS with a same-origin allowlist and reject other origins.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/davila7/claude-code-templates/security/advisories/GHSA-79wm-x847-7cvg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73222" + }, + { + "type": "WEB", + "url": "https://github.com/davila7/claude-code-templates/commit/bc4618b07232633c1c0aac12a43e436268d31783" + }, + { + "type": "PACKAGE", + "url": "https://github.com/davila7/claude-code-templates" + }, + { + "type": "WEB", + "url": "https://github.com/davila7/claude-code-templates/blob/main/CHANGELOG.md" + } + ] +} diff --git a/advisories/BREW-cobo-cli-CVE-2026-76221.json b/advisories/BREW-cobo-cli-CVE-2026-76221.json index 5ad3575d1b9..d36a26716b7 100644 --- a/advisories/BREW-cobo-cli-CVE-2026-76221.json +++ b/advisories/BREW-cobo-cli-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cobo-cli-CVE-2026-76221", "published": "2026-08-20T08:43:30Z", - "modified": "2026-08-29T08:43:55Z", + "modified": "2026-09-04T08:51:28Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -44,6 +45,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cobo-cli-CVE-2026-76222.json b/advisories/BREW-cobo-cli-CVE-2026-76222.json index 15ff6c519e9..6c90373abed 100644 --- a/advisories/BREW-cobo-cli-CVE-2026-76222.json +++ b/advisories/BREW-cobo-cli-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cobo-cli-CVE-2026-76222", "published": "2026-08-20T08:43:30Z", - "modified": "2026-08-29T08:43:55Z", + "modified": "2026-09-04T08:51:28Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -44,6 +45,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cobo-cli-CVE-2026-78675.json b/advisories/BREW-cobo-cli-CVE-2026-78675.json new file mode 100644 index 00000000000..dcfc5749a24 --- /dev/null +++ b/advisories/BREW-cobo-cli-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cobo-cli-CVE-2026-78675", + "published": "2026-09-04T08:51:28Z", + "modified": "2026-09-04T08:51:28Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cobo-cli", + "purl": "pkg:brew/cobo-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.50" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-cobo-cli-CVE-2026-78676.json b/advisories/BREW-cobo-cli-CVE-2026-78676.json new file mode 100644 index 00000000000..f92e53f45e5 --- /dev/null +++ b/advisories/BREW-cobo-cli-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cobo-cli-CVE-2026-78676", + "published": "2026-09-04T08:51:28Z", + "modified": "2026-09-04T08:51:28Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cobo-cli", + "purl": "pkg:brew/cobo-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.50" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-cobo-cli-CVE-2026-78677.json b/advisories/BREW-cobo-cli-CVE-2026-78677.json new file mode 100644 index 00000000000..ad746195ea3 --- /dev/null +++ b/advisories/BREW-cobo-cli-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cobo-cli-CVE-2026-78677", + "published": "2026-09-04T08:51:28Z", + "modified": "2026-09-04T08:51:28Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cobo-cli", + "purl": "pkg:brew/cobo-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.50" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-cobo-cli-CVE-2026-78678.json b/advisories/BREW-cobo-cli-CVE-2026-78678.json new file mode 100644 index 00000000000..cfa9e42ea9b --- /dev/null +++ b/advisories/BREW-cobo-cli-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cobo-cli-CVE-2026-78678", + "published": "2026-09-04T08:51:28Z", + "modified": "2026-09-04T08:51:28Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cobo-cli", + "purl": "pkg:brew/cobo-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.50" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-cobo-cli-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-cobo-cli-GHSA-hmq2-w58f-27jc.json index 1222602b3be..7a7bfb4db0c 100644 --- a/advisories/BREW-cobo-cli-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-cobo-cli-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cobo-cli-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:40:10Z", - "modified": "2026-08-29T08:43:55Z", + "modified": "2026-09-04T08:51:28Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -44,6 +45,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cobo-cli-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-cobo-cli-GHSA-jm78-9fvv-mhgr.json index ef83a78368c..5be80e53fda 100644 --- a/advisories/BREW-cobo-cli-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-cobo-cli-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cobo-cli-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:40:10Z", - "modified": "2026-08-29T08:43:55Z", + "modified": "2026-09-04T08:51:28Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -44,6 +45,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.50", + "key": "pkg:pypi/gitpython@3.1.50", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-conda-lock-CVE-2026-76221.json b/advisories/BREW-conda-lock-CVE-2026-76221.json index 88784d39d46..67f8b125e58 100644 --- a/advisories/BREW-conda-lock-CVE-2026-76221.json +++ b/advisories/BREW-conda-lock-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-conda-lock-CVE-2026-76221", "published": "2026-08-20T08:44:16Z", - "modified": "2026-08-20T08:44:16Z", + "modified": "2026-09-04T08:51:51Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-conda-lock-CVE-2026-76222.json b/advisories/BREW-conda-lock-CVE-2026-76222.json index ab0e9f07aaf..4c29d8410bd 100644 --- a/advisories/BREW-conda-lock-CVE-2026-76222.json +++ b/advisories/BREW-conda-lock-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-conda-lock-CVE-2026-76222", "published": "2026-08-20T08:44:16Z", - "modified": "2026-08-20T08:44:16Z", + "modified": "2026-09-04T08:51:51Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-conda-lock-CVE-2026-78675.json b/advisories/BREW-conda-lock-CVE-2026-78675.json new file mode 100644 index 00000000000..3bc5bf79f5e --- /dev/null +++ b/advisories/BREW-conda-lock-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-conda-lock-CVE-2026-78675", + "published": "2026-09-04T08:51:51Z", + "modified": "2026-09-04T08:51:51Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "conda-lock", + "purl": "pkg:brew/conda-lock" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-conda-lock-CVE-2026-78676.json b/advisories/BREW-conda-lock-CVE-2026-78676.json new file mode 100644 index 00000000000..b72df10415d --- /dev/null +++ b/advisories/BREW-conda-lock-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-conda-lock-CVE-2026-78676", + "published": "2026-09-04T08:51:51Z", + "modified": "2026-09-04T08:51:51Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "conda-lock", + "purl": "pkg:brew/conda-lock" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-conda-lock-CVE-2026-78677.json b/advisories/BREW-conda-lock-CVE-2026-78677.json new file mode 100644 index 00000000000..051be4ee307 --- /dev/null +++ b/advisories/BREW-conda-lock-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-conda-lock-CVE-2026-78677", + "published": "2026-09-04T08:51:51Z", + "modified": "2026-09-04T08:51:51Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "conda-lock", + "purl": "pkg:brew/conda-lock" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-conda-lock-CVE-2026-78678.json b/advisories/BREW-conda-lock-CVE-2026-78678.json new file mode 100644 index 00000000000..4de7233ecfc --- /dev/null +++ b/advisories/BREW-conda-lock-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-conda-lock-CVE-2026-78678", + "published": "2026-09-04T08:51:51Z", + "modified": "2026-09-04T08:51:51Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "conda-lock", + "purl": "pkg:brew/conda-lock" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-conda-lock-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-conda-lock-GHSA-hmq2-w58f-27jc.json index 795b61b515d..024e1f99f2b 100644 --- a/advisories/BREW-conda-lock-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-conda-lock-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-conda-lock-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:41:05Z", - "modified": "2026-08-29T08:44:26Z", + "modified": "2026-09-04T08:51:51Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-conda-lock-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-conda-lock-GHSA-jm78-9fvv-mhgr.json index c9278602880..1c60a32ecb0 100644 --- a/advisories/BREW-conda-lock-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-conda-lock-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-conda-lock-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:41:05Z", - "modified": "2026-08-29T08:44:26Z", + "modified": "2026-09-04T08:51:51Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cruft-CVE-2026-76221.json b/advisories/BREW-cruft-CVE-2026-76221.json index c2a31c03cf4..903994999d3 100644 --- a/advisories/BREW-cruft-CVE-2026-76221.json +++ b/advisories/BREW-cruft-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cruft-CVE-2026-76221", "published": "2026-08-20T08:44:24Z", - "modified": "2026-08-20T08:44:24Z", + "modified": "2026-09-04T08:52:00Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cruft-CVE-2026-76222.json b/advisories/BREW-cruft-CVE-2026-76222.json index a1d3019e1d9..300dbbb2193 100644 --- a/advisories/BREW-cruft-CVE-2026-76222.json +++ b/advisories/BREW-cruft-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cruft-CVE-2026-76222", "published": "2026-08-20T08:44:24Z", - "modified": "2026-08-20T08:44:24Z", + "modified": "2026-09-04T08:52:00Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cruft-CVE-2026-78675.json b/advisories/BREW-cruft-CVE-2026-78675.json new file mode 100644 index 00000000000..5951a8fd1d1 --- /dev/null +++ b/advisories/BREW-cruft-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cruft-CVE-2026-78675", + "published": "2026-09-04T08:52:00Z", + "modified": "2026-09-04T08:52:00Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cruft", + "purl": "pkg:brew/cruft" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-cruft-CVE-2026-78676.json b/advisories/BREW-cruft-CVE-2026-78676.json new file mode 100644 index 00000000000..afe3bc65c46 --- /dev/null +++ b/advisories/BREW-cruft-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cruft-CVE-2026-78676", + "published": "2026-09-04T08:52:00Z", + "modified": "2026-09-04T08:52:00Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cruft", + "purl": "pkg:brew/cruft" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-cruft-CVE-2026-78677.json b/advisories/BREW-cruft-CVE-2026-78677.json new file mode 100644 index 00000000000..b19f0c11420 --- /dev/null +++ b/advisories/BREW-cruft-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cruft-CVE-2026-78677", + "published": "2026-09-04T08:52:00Z", + "modified": "2026-09-04T08:52:00Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cruft", + "purl": "pkg:brew/cruft" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-cruft-CVE-2026-78678.json b/advisories/BREW-cruft-CVE-2026-78678.json new file mode 100644 index 00000000000..249c68ac14e --- /dev/null +++ b/advisories/BREW-cruft-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cruft-CVE-2026-78678", + "published": "2026-09-04T08:52:00Z", + "modified": "2026-09-04T08:52:00Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cruft", + "purl": "pkg:brew/cruft" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-cruft-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-cruft-GHSA-hmq2-w58f-27jc.json index 881e8d745b7..f9b9d3ecf31 100644 --- a/advisories/BREW-cruft-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-cruft-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cruft-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-29T08:44:34Z", + "modified": "2026-09-04T08:52:00Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cruft-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-cruft-GHSA-jm78-9fvv-mhgr.json index 33c2b47a22f..4fa59ec1ace 100644 --- a/advisories/BREW-cruft-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-cruft-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cruft-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:41:15Z", - "modified": "2026-08-29T08:44:34Z", + "modified": "2026-09-04T08:52:00Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cycode-CVE-2026-76221.json b/advisories/BREW-cycode-CVE-2026-76221.json index 84165434cc2..b8241c53b22 100644 --- a/advisories/BREW-cycode-CVE-2026-76221.json +++ b/advisories/BREW-cycode-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cycode-CVE-2026-76221", "published": "2026-08-20T08:45:02Z", - "modified": "2026-09-02T08:51:49Z", + "modified": "2026-09-04T08:54:03Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cycode-CVE-2026-76222.json b/advisories/BREW-cycode-CVE-2026-76222.json index 55ef40708e1..d5c8c10b89e 100644 --- a/advisories/BREW-cycode-CVE-2026-76222.json +++ b/advisories/BREW-cycode-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cycode-CVE-2026-76222", "published": "2026-08-20T08:45:02Z", - "modified": "2026-09-02T08:51:49Z", + "modified": "2026-09-04T08:54:03Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cycode-CVE-2026-78675.json b/advisories/BREW-cycode-CVE-2026-78675.json new file mode 100644 index 00000000000..0ad48dad25a --- /dev/null +++ b/advisories/BREW-cycode-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cycode-CVE-2026-78675", + "published": "2026-09-04T08:54:09Z", + "modified": "2026-09-04T08:54:09Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cycode", + "purl": "pkg:brew/cycode" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.19.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-cycode-CVE-2026-78676.json b/advisories/BREW-cycode-CVE-2026-78676.json new file mode 100644 index 00000000000..39a5a77d997 --- /dev/null +++ b/advisories/BREW-cycode-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cycode-CVE-2026-78676", + "published": "2026-09-04T08:54:09Z", + "modified": "2026-09-04T08:54:09Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cycode", + "purl": "pkg:brew/cycode" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.19.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-cycode-CVE-2026-78677.json b/advisories/BREW-cycode-CVE-2026-78677.json new file mode 100644 index 00000000000..16eaefda950 --- /dev/null +++ b/advisories/BREW-cycode-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cycode-CVE-2026-78677", + "published": "2026-09-04T08:54:09Z", + "modified": "2026-09-04T08:54:09Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cycode", + "purl": "pkg:brew/cycode" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.19.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-cycode-CVE-2026-78678.json b/advisories/BREW-cycode-CVE-2026-78678.json new file mode 100644 index 00000000000..c2f86f7ebc2 --- /dev/null +++ b/advisories/BREW-cycode-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-cycode-CVE-2026-78678", + "published": "2026-09-04T08:54:09Z", + "modified": "2026-09-04T08:54:09Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "cycode", + "purl": "pkg:brew/cycode" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.19.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-cycode-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-cycode-GHSA-hmq2-w58f-27jc.json index 00bdbe5ea70..8bec21cd5c1 100644 --- a/advisories/BREW-cycode-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-cycode-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cycode-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:42:07Z", - "modified": "2026-09-02T08:51:49Z", + "modified": "2026-09-04T08:54:03Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-cycode-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-cycode-GHSA-jm78-9fvv-mhgr.json index 5426cdf23d1..9a5032e7241 100644 --- a/advisories/BREW-cycode-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-cycode-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-cycode-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:42:07Z", - "modified": "2026-09-02T08:51:49Z", + "modified": "2026-09-04T08:54:03Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-djlint-CVE-2026-7246.json b/advisories/BREW-djlint-CVE-2026-7246.json index adf396a7ad0..3db2fe64483 100644 --- a/advisories/BREW-djlint-CVE-2026-7246.json +++ b/advisories/BREW-djlint-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-djlint-CVE-2026-7246", "published": "2026-08-13T16:42:58Z", - "modified": "2026-08-13T16:42:58Z", + "modified": "2026-09-04T08:55:04Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-dstack-CVE-2026-76221.json b/advisories/BREW-dstack-CVE-2026-76221.json index a2e5777edb8..6129693895c 100644 --- a/advisories/BREW-dstack-CVE-2026-76221.json +++ b/advisories/BREW-dstack-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2026-76221", "published": "2026-08-20T08:46:26Z", - "modified": "2026-08-29T08:47:36Z", + "modified": "2026-09-04T08:56:04Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dstack-CVE-2026-76222.json b/advisories/BREW-dstack-CVE-2026-76222.json index 74b23657ffc..d3a4df94fbd 100644 --- a/advisories/BREW-dstack-CVE-2026-76222.json +++ b/advisories/BREW-dstack-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dstack-CVE-2026-76222", "published": "2026-08-20T08:46:26Z", - "modified": "2026-08-29T08:47:36Z", + "modified": "2026-09-04T08:56:04Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dstack-CVE-2026-78675.json b/advisories/BREW-dstack-CVE-2026-78675.json new file mode 100644 index 00000000000..1b726b461dd --- /dev/null +++ b/advisories/BREW-dstack-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dstack-CVE-2026-78675", + "published": "2026-09-04T08:56:11Z", + "modified": "2026-09-04T08:56:11Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dstack", + "purl": "pkg:brew/dstack" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-dstack-CVE-2026-78676.json b/advisories/BREW-dstack-CVE-2026-78676.json new file mode 100644 index 00000000000..1aef1e1c58b --- /dev/null +++ b/advisories/BREW-dstack-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dstack-CVE-2026-78676", + "published": "2026-09-04T08:56:11Z", + "modified": "2026-09-04T08:56:11Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dstack", + "purl": "pkg:brew/dstack" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-dstack-CVE-2026-78677.json b/advisories/BREW-dstack-CVE-2026-78677.json new file mode 100644 index 00000000000..883534d386e --- /dev/null +++ b/advisories/BREW-dstack-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dstack-CVE-2026-78677", + "published": "2026-09-04T08:56:11Z", + "modified": "2026-09-04T08:56:11Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dstack", + "purl": "pkg:brew/dstack" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-dstack-CVE-2026-78678.json b/advisories/BREW-dstack-CVE-2026-78678.json new file mode 100644 index 00000000000..1157a19da90 --- /dev/null +++ b/advisories/BREW-dstack-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dstack-CVE-2026-78678", + "published": "2026-09-04T08:56:11Z", + "modified": "2026-09-04T08:56:11Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dstack", + "purl": "pkg:brew/dstack" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-dstack-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-dstack-GHSA-hmq2-w58f-27jc.json index a9cd069b629..a050161021b 100644 --- a/advisories/BREW-dstack-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-dstack-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dstack-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-29T08:47:36Z", + "modified": "2026-09-04T08:56:04Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dstack-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-dstack-GHSA-jm78-9fvv-mhgr.json index e0bd791f2cb..38a6a97f946 100644 --- a/advisories/BREW-dstack-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-dstack-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dstack-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:43:57Z", - "modified": "2026-08-29T08:47:36Z", + "modified": "2026-09-04T08:56:04Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dvc-CVE-2026-76221.json b/advisories/BREW-dvc-CVE-2026-76221.json index caeef48953d..94bfa2c34c2 100644 --- a/advisories/BREW-dvc-CVE-2026-76221.json +++ b/advisories/BREW-dvc-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dvc-CVE-2026-76221", "published": "2026-08-20T08:46:31Z", - "modified": "2026-08-20T08:46:31Z", + "modified": "2026-09-04T08:56:18Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dvc-CVE-2026-76222.json b/advisories/BREW-dvc-CVE-2026-76222.json index de7188520f7..ec33042ead3 100644 --- a/advisories/BREW-dvc-CVE-2026-76222.json +++ b/advisories/BREW-dvc-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dvc-CVE-2026-76222", "published": "2026-08-20T08:46:31Z", - "modified": "2026-08-20T08:46:31Z", + "modified": "2026-09-04T08:56:18Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dvc-CVE-2026-78675.json b/advisories/BREW-dvc-CVE-2026-78675.json new file mode 100644 index 00000000000..d19275af210 --- /dev/null +++ b/advisories/BREW-dvc-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dvc-CVE-2026-78675", + "published": "2026-09-04T08:56:18Z", + "modified": "2026-09-04T08:56:18Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dvc", + "purl": "pkg:brew/dvc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-dvc-CVE-2026-78676.json b/advisories/BREW-dvc-CVE-2026-78676.json new file mode 100644 index 00000000000..08ce8052bc2 --- /dev/null +++ b/advisories/BREW-dvc-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dvc-CVE-2026-78676", + "published": "2026-09-04T08:56:18Z", + "modified": "2026-09-04T08:56:18Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dvc", + "purl": "pkg:brew/dvc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-dvc-CVE-2026-78677.json b/advisories/BREW-dvc-CVE-2026-78677.json new file mode 100644 index 00000000000..e9000671740 --- /dev/null +++ b/advisories/BREW-dvc-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dvc-CVE-2026-78677", + "published": "2026-09-04T08:56:18Z", + "modified": "2026-09-04T08:56:18Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dvc", + "purl": "pkg:brew/dvc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-dvc-CVE-2026-78678.json b/advisories/BREW-dvc-CVE-2026-78678.json new file mode 100644 index 00000000000..7b853f4c235 --- /dev/null +++ b/advisories/BREW-dvc-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-dvc-CVE-2026-78678", + "published": "2026-09-04T08:56:18Z", + "modified": "2026-09-04T08:56:18Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "dvc", + "purl": "pkg:brew/dvc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-dvc-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-dvc-GHSA-hmq2-w58f-27jc.json index 57e3644ded2..e9a97e8e8f3 100644 --- a/advisories/BREW-dvc-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-dvc-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dvc-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:44:03Z", - "modified": "2026-08-29T08:47:42Z", + "modified": "2026-09-04T08:56:18Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-dvc-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-dvc-GHSA-jm78-9fvv-mhgr.json index 69a58e34f67..eef483faf90 100644 --- a/advisories/BREW-dvc-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-dvc-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-dvc-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:44:03Z", - "modified": "2026-08-29T08:47:42Z", + "modified": "2026-09-04T08:56:18Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-esptool-CVE-2015-8557.json b/advisories/BREW-esptool-CVE-2015-8557.json index 2bfc83b0393..850ceed084d 100644 --- a/advisories/BREW-esptool-CVE-2015-8557.json +++ b/advisories/BREW-esptool-CVE-2015-8557.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2015-8557", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-fff8-4w9p-7v76", "CVE-2015-8557", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esptool-CVE-2018-1000518.json b/advisories/BREW-esptool-CVE-2018-1000518.json new file mode 100644 index 00000000000..c0a07bf906b --- /dev/null +++ b/advisories/BREW-esptool-CVE-2018-1000518.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-esptool-CVE-2018-1000518", + "published": "2026-09-04T08:57:54Z", + "modified": "2026-09-04T08:57:54Z", + "upstream": [ + "GHSA-6g87-ff9q-v847", + "CVE-2018-1000518", + "PYSEC-2018-79" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "esptool", + "purl": "pkg:brew/esptool" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.0", + "resource": "websockets", + "resource_purl": "pkg:pypi/websockets@17.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "17.1", + "key": "pkg:pypi/websockets@17.1", + "resource": "websockets" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "17.1", + "key": "pkg:pypi/websockets@17.1", + "resource": "websockets" + } + ] + }, + "summary": "websockets is vulnerable to denial of service by memory exhaustion", + "details": "The Python websockets library version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appears to be exploitable via sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in version 5.0", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000518" + }, + { + "type": "WEB", + "url": "https://github.com/aaugustin/websockets/pull/407" + }, + { + "type": "PACKAGE", + "url": "https://github.com/aaugustin/websockets" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/websockets/PYSEC-2018-79.yaml" + } + ] +} diff --git a/advisories/BREW-esptool-CVE-2021-20270.json b/advisories/BREW-esptool-CVE-2021-20270.json index 2dc43318343..57b57bde5c5 100644 --- a/advisories/BREW-esptool-CVE-2021-20270.json +++ b/advisories/BREW-esptool-CVE-2021-20270.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2021-20270", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-9w8r-397f-prfh", "CVE-2021-20270", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esptool-CVE-2021-27291.json b/advisories/BREW-esptool-CVE-2021-27291.json index 2bc4e6b3852..180dc2e0200 100644 --- a/advisories/BREW-esptool-CVE-2021-27291.json +++ b/advisories/BREW-esptool-CVE-2021-27291.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2021-27291", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-pq64-v7f5-gqh8", "CVE-2021-27291", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.7.4", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esptool-CVE-2021-33880.json b/advisories/BREW-esptool-CVE-2021-33880.json new file mode 100644 index 00000000000..356a11c7660 --- /dev/null +++ b/advisories/BREW-esptool-CVE-2021-33880.json @@ -0,0 +1,101 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-esptool-CVE-2021-33880", + "published": "2026-09-04T08:57:54Z", + "modified": "2026-09-04T08:57:54Z", + "upstream": [ + "GHSA-8ch4-58qp-g3mp", + "CVE-2021-33880", + "PYSEC-2021-95" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "esptool", + "purl": "pkg:brew/esptool" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.0_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "9.1", + "resource": "websockets", + "resource_purl": "pkg:pypi/websockets@17.1" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "17.1", + "key": "pkg:pypi/websockets@17.1", + "resource": "websockets" + }, + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "websockets", + "subject_version": "17.1", + "key": "pkg:pypi/websockets@17.1", + "resource": "websockets" + } + ] + }, + "summary": "Observable Timing Discrepancy in aaugustin websockets library", + "details": "The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33880" + }, + { + "type": "WEB", + "url": "https://github.com/aaugustin/websockets/commit/547a26b685d08cac0aa64e5e65f7867ac0ea9bc0" + }, + { + "type": "WEB", + "url": "https://github.com/aaugustin/websockets" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/websockets/PYSEC-2021-95.yaml" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujan2022.html" + } + ] +} diff --git a/advisories/BREW-esptool-CVE-2022-40896.json b/advisories/BREW-esptool-CVE-2022-40896.json index a499412480c..4a9857aeba6 100644 --- a/advisories/BREW-esptool-CVE-2022-40896.json +++ b/advisories/BREW-esptool-CVE-2022-40896.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2022-40896", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-mrwq-x4v8-fh7p", "CVE-2022-40896", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.15.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esptool-CVE-2023-46894.json b/advisories/BREW-esptool-CVE-2023-46894.json index cb9256bdaf9..55f31b7d5be 100644 --- a/advisories/BREW-esptool-CVE-2023-46894.json +++ b/advisories/BREW-esptool-CVE-2023-46894.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2023-46894", "published": "2026-08-13T16:45:08Z", - "modified": "2026-09-03T08:57:54Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-3f38-96qm-r3fw", "CVE-2023-46894" @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "esptool", - "subject_version": "5.3.1", - "key": "pkg:pypi/esptool@5.3.1" + "subject_version": "5.4.0", + "key": "pkg:pypi/esptool@5.4.0" }, { "strategy": "distro", @@ -55,8 +55,8 @@ "strategy": "distro", "ecosystem": "PyPI", "name": "esptool", - "subject_version": "5.3.1", - "key": "upstream:pkg:pypi/esptool@5.3.1" + "subject_version": "5.4.0", + "key": "upstream:pkg:pypi/esptool@5.4.0" } ] }, diff --git a/advisories/BREW-esptool-CVE-2026-4539.json b/advisories/BREW-esptool-CVE-2026-4539.json index 2472fff8840..33a9181c8e5 100644 --- a/advisories/BREW-esptool-CVE-2026-4539.json +++ b/advisories/BREW-esptool-CVE-2026-4539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2026-4539", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "GHSA-5239-wwwm-4pmq", "CVE-2026-4539", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.20.0", "resource": "pygments", - "resource_purl": "pkg:pypi/pygments@2.20.0" + "resource_purl": "pkg:pypi/pygments@2.21.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pygments", - "subject_version": "2.20.0", - "key": "pkg:pypi/pygments@2.20.0", + "subject_version": "2.21.0", + "key": "pkg:pypi/pygments@2.21.0", "resource": "pygments" } ] diff --git a/advisories/BREW-esptool-CVE-2026-7246.json b/advisories/BREW-esptool-CVE-2026-7246.json index 7c0abe32d58..b872eb90708 100644 --- a/advisories/BREW-esptool-CVE-2026-7246.json +++ b/advisories/BREW-esptool-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-esptool-CVE-2026-7246", "published": "2026-08-13T16:45:08Z", - "modified": "2026-08-13T16:45:08Z", + "modified": "2026-09-04T08:57:20Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-fastmcp-CVE-2025-62800.json b/advisories/BREW-fastmcp-CVE-2025-62800.json index f5e27368a54..c6fe7111380 100644 --- a/advisories/BREW-fastmcp-CVE-2025-62800.json +++ b/advisories/BREW-fastmcp-CVE-2025-62800.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2025-62800", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-mxxr-jv3v-6pgc", "CVE-2025-62800", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-CVE-2025-62801.json b/advisories/BREW-fastmcp-CVE-2025-62801.json index 26975dc366e..5a8b9f0f394 100644 --- a/advisories/BREW-fastmcp-CVE-2025-62801.json +++ b/advisories/BREW-fastmcp-CVE-2025-62801.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2025-62801", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-rj5c-58rq-j5g5", "CVE-2025-62801", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-CVE-2025-64340.json b/advisories/BREW-fastmcp-CVE-2025-64340.json index 70604579cd7..d54c373d4f6 100644 --- a/advisories/BREW-fastmcp-CVE-2025-64340.json +++ b/advisories/BREW-fastmcp-CVE-2025-64340.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2025-64340", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-m8x7-r2rg-vh5g", "CVE-2025-64340", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-CVE-2025-69196.json b/advisories/BREW-fastmcp-CVE-2025-69196.json index 77383c72a98..5411b02158b 100644 --- a/advisories/BREW-fastmcp-CVE-2025-69196.json +++ b/advisories/BREW-fastmcp-CVE-2025-69196.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2025-69196", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-5h2m-4q8j-pqpj", "CVE-2025-69196", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-CVE-2026-27124.json b/advisories/BREW-fastmcp-CVE-2026-27124.json index be068a63a96..d0b6945dc08 100644 --- a/advisories/BREW-fastmcp-CVE-2026-27124.json +++ b/advisories/BREW-fastmcp-CVE-2026-27124.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2026-27124", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-rww4-4w9c-7733", "CVE-2026-27124", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-CVE-2026-32871.json b/advisories/BREW-fastmcp-CVE-2026-32871.json index 30e94f7f8ef..24648a9a1cf 100644 --- a/advisories/BREW-fastmcp-CVE-2026-32871.json +++ b/advisories/BREW-fastmcp-CVE-2026-32871.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-CVE-2026-32871", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-vv7q-7jx5-f767", "CVE-2026-32871", @@ -44,15 +44,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-GHSA-c2jp-c369-7pvx.json b/advisories/BREW-fastmcp-GHSA-c2jp-c369-7pvx.json index 62a4f5cbce3..6fadf68cd7c 100644 --- a/advisories/BREW-fastmcp-GHSA-c2jp-c369-7pvx.json +++ b/advisories/BREW-fastmcp-GHSA-c2jp-c369-7pvx.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-GHSA-c2jp-c369-7pvx", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-c2jp-c369-7pvx" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fastmcp-GHSA-rcfx-77hg-w2wv.json b/advisories/BREW-fastmcp-GHSA-rcfx-77hg-w2wv.json index 453bcdcfed5..6cc20f7a32b 100644 --- a/advisories/BREW-fastmcp-GHSA-rcfx-77hg-w2wv.json +++ b/advisories/BREW-fastmcp-GHSA-rcfx-77hg-w2wv.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-fastmcp-GHSA-rcfx-77hg-w2wv", "published": "2026-08-13T16:46:31Z", - "modified": "2026-09-03T08:59:30Z", + "modified": "2026-09-04T08:59:23Z", "upstream": [ "GHSA-rcfx-77hg-w2wv" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "fastmcp", - "subject_version": "4.0.1", - "key": "pkg:pypi/fastmcp@4.0.1" + "subject_version": "4.0.2", + "key": "pkg:pypi/fastmcp@4.0.2" } ] }, diff --git a/advisories/BREW-fdroidserver-CVE-2026-76221.json b/advisories/BREW-fdroidserver-CVE-2026-76221.json index b908ee2fa47..0e912163605 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76221.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76221", "published": "2026-08-20T08:51:09Z", - "modified": "2026-08-20T08:51:09Z", + "modified": "2026-09-04T08:59:24Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-76222.json b/advisories/BREW-fdroidserver-CVE-2026-76222.json index 5f581b962ea..4e4c5b0944b 100644 --- a/advisories/BREW-fdroidserver-CVE-2026-76222.json +++ b/advisories/BREW-fdroidserver-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-CVE-2026-76222", "published": "2026-08-20T08:51:09Z", - "modified": "2026-08-20T08:51:09Z", + "modified": "2026-09-04T08:59:24Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-CVE-2026-78675.json b/advisories/BREW-fdroidserver-CVE-2026-78675.json new file mode 100644 index 00000000000..a4d0858f0b6 --- /dev/null +++ b/advisories/BREW-fdroidserver-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-fdroidserver-CVE-2026-78675", + "published": "2026-09-04T08:59:24Z", + "modified": "2026-09-04T08:59:24Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "fdroidserver", + "purl": "pkg:brew/fdroidserver" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-fdroidserver-CVE-2026-78676.json b/advisories/BREW-fdroidserver-CVE-2026-78676.json new file mode 100644 index 00000000000..939f46111c7 --- /dev/null +++ b/advisories/BREW-fdroidserver-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-fdroidserver-CVE-2026-78676", + "published": "2026-09-04T08:59:24Z", + "modified": "2026-09-04T08:59:24Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "fdroidserver", + "purl": "pkg:brew/fdroidserver" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-fdroidserver-CVE-2026-78677.json b/advisories/BREW-fdroidserver-CVE-2026-78677.json new file mode 100644 index 00000000000..331ac931a41 --- /dev/null +++ b/advisories/BREW-fdroidserver-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-fdroidserver-CVE-2026-78677", + "published": "2026-09-04T08:59:24Z", + "modified": "2026-09-04T08:59:24Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "fdroidserver", + "purl": "pkg:brew/fdroidserver" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-fdroidserver-CVE-2026-78678.json b/advisories/BREW-fdroidserver-CVE-2026-78678.json new file mode 100644 index 00000000000..bea77d38f97 --- /dev/null +++ b/advisories/BREW-fdroidserver-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-fdroidserver-CVE-2026-78678", + "published": "2026-09-04T08:59:24Z", + "modified": "2026-09-04T08:59:24Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "fdroidserver", + "purl": "pkg:brew/fdroidserver" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-fdroidserver-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-fdroidserver-GHSA-hmq2-w58f-27jc.json index eb67f2dcc42..83db87b09ea 100644 --- a/advisories/BREW-fdroidserver-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-fdroidserver-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-29T08:50:16Z", + "modified": "2026-09-04T08:59:24Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-fdroidserver-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-fdroidserver-GHSA-jm78-9fvv-mhgr.json index 386f2d695d0..290caf217f0 100644 --- a/advisories/BREW-fdroidserver-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-fdroidserver-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-fdroidserver-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:46:32Z", - "modified": "2026-08-29T08:50:16Z", + "modified": "2026-09-04T08:59:24Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-firebase-cli-CVE-2024-4128.json b/advisories/BREW-firebase-cli-CVE-2024-4128.json index e60012a31d3..1dc90d783b8 100644 --- a/advisories/BREW-firebase-cli-CVE-2024-4128.json +++ b/advisories/BREW-firebase-cli-CVE-2024-4128.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-firebase-cli-CVE-2024-4128", "published": "2026-08-13T16:47:26Z", - "modified": "2026-08-29T08:51:11Z", + "modified": "2026-09-04T09:00:28Z", "upstream": [ "GHSA-rcm2-22f3-pqv3", "CVE-2024-4128", @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "firebase-tools", - "subject_version": "15.28.2", - "key": "pkg:npm/firebase-tools@15.28.2" + "subject_version": "15.29.0", + "key": "pkg:npm/firebase-tools@15.29.0" } ] }, diff --git a/advisories/BREW-gitup-CVE-2026-76221.json b/advisories/BREW-gitup-CVE-2026-76221.json index 42744739935..b3c64c0cbe3 100644 --- a/advisories/BREW-gitup-CVE-2026-76221.json +++ b/advisories/BREW-gitup-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-gitup-CVE-2026-76221", "published": "2026-08-20T08:55:17Z", - "modified": "2026-08-20T08:55:17Z", + "modified": "2026-09-04T09:04:14Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-gitup-CVE-2026-76222.json b/advisories/BREW-gitup-CVE-2026-76222.json index 6d65d4228b1..57aa57490a4 100644 --- a/advisories/BREW-gitup-CVE-2026-76222.json +++ b/advisories/BREW-gitup-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-gitup-CVE-2026-76222", "published": "2026-08-20T08:55:17Z", - "modified": "2026-08-20T08:55:17Z", + "modified": "2026-09-04T09:04:14Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-gitup-CVE-2026-78675.json b/advisories/BREW-gitup-CVE-2026-78675.json new file mode 100644 index 00000000000..51d45234f30 --- /dev/null +++ b/advisories/BREW-gitup-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gitup-CVE-2026-78675", + "published": "2026-09-04T09:04:14Z", + "modified": "2026-09-04T09:04:14Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gitup", + "purl": "pkg:brew/gitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-gitup-CVE-2026-78676.json b/advisories/BREW-gitup-CVE-2026-78676.json new file mode 100644 index 00000000000..49a5fda8005 --- /dev/null +++ b/advisories/BREW-gitup-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gitup-CVE-2026-78676", + "published": "2026-09-04T09:04:14Z", + "modified": "2026-09-04T09:04:14Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gitup", + "purl": "pkg:brew/gitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-gitup-CVE-2026-78677.json b/advisories/BREW-gitup-CVE-2026-78677.json new file mode 100644 index 00000000000..5b7754a96f5 --- /dev/null +++ b/advisories/BREW-gitup-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gitup-CVE-2026-78677", + "published": "2026-09-04T09:04:14Z", + "modified": "2026-09-04T09:04:14Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gitup", + "purl": "pkg:brew/gitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-gitup-CVE-2026-78678.json b/advisories/BREW-gitup-CVE-2026-78678.json new file mode 100644 index 00000000000..c1a8b85d300 --- /dev/null +++ b/advisories/BREW-gitup-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gitup-CVE-2026-78678", + "published": "2026-09-04T09:04:14Z", + "modified": "2026-09-04T09:04:14Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gitup", + "purl": "pkg:brew/gitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-gitup-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-gitup-GHSA-hmq2-w58f-27jc.json index 0512e779b1b..31d5c6bafda 100644 --- a/advisories/BREW-gitup-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-gitup-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-gitup-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T16:51:23Z", - "modified": "2026-08-29T08:55:01Z", + "modified": "2026-09-04T09:04:14Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-gitup-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-gitup-GHSA-jm78-9fvv-mhgr.json index 97a82142fe9..2ec1c1bffbf 100644 --- a/advisories/BREW-gitup-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-gitup-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-gitup-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T16:51:23Z", - "modified": "2026-08-29T08:55:01Z", + "modified": "2026-09-04T09:04:14Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-glances-CVE-2024-33663.json b/advisories/BREW-glances-CVE-2024-33663.json index e99b774adc0..f0d60b3a9e2 100644 --- a/advisories/BREW-glances-CVE-2024-33663.json +++ b/advisories/BREW-glances-CVE-2024-33663.json @@ -2,11 +2,12 @@ "schema_version": "1.7.3", "id": "BREW-glances-CVE-2024-33663", "published": "2026-08-13T16:51:23Z", - "modified": "2026-08-13T16:51:23Z", + "modified": "2026-09-04T09:04:14Z", "upstream": [ "GHSA-6c5p-j8vq-pqhj", "CVE-2024-33663", - "PYSEC-2024-232" + "PYSEC-2024-232", + "CVE-2026-85394" ], "affected": [ { diff --git a/advisories/BREW-gptline-CVE-2026-62384.json b/advisories/BREW-gptline-CVE-2026-62384.json new file mode 100644 index 00000000000..8237cce35a2 --- /dev/null +++ b/advisories/BREW-gptline-CVE-2026-62384.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-gptline-CVE-2026-62384", + "published": "2026-09-04T09:08:36Z", + "modified": "2026-09-04T09:08:36Z", + "upstream": [ + "PYSEC-2026-3789", + "CVE-2026-62384", + "GHSA-f833-7jw8-xwrv" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "gptline", + "purl": "pkg:brew/gptline" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.8_23" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.10.2", + "resource": "nltk", + "resource_purl": "pkg:pypi/nltk@3.10.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + } + ] + }, + "details": "NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/nltk-framenetcorpusreader-symlink-sandbox-bypass-before" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv" + } + ] +} diff --git a/advisories/BREW-gptline-CVE-2026-71514.json b/advisories/BREW-gptline-CVE-2026-71514.json index 7844f14f5f7..6a709384e2c 100644 --- a/advisories/BREW-gptline-CVE-2026-71514.json +++ b/advisories/BREW-gptline-CVE-2026-71514.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-gptline-CVE-2026-71514", "published": "2026-09-03T09:08:38Z", - "modified": "2026-09-03T09:08:38Z", + "modified": "2026-09-04T09:07:33Z", "upstream": [ "GHSA-cv22-g7mw-8v73", - "CVE-2026-71514" + "CVE-2026-71514", + "PYSEC-2026-3790" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-harlequin-CVE-2026-7246.json b/advisories/BREW-harlequin-CVE-2026-7246.json index af872cbe9bf..1e05f0bcd1d 100644 --- a/advisories/BREW-harlequin-CVE-2026-7246.json +++ b/advisories/BREW-harlequin-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-harlequin-CVE-2026-7246", "published": "2026-08-13T16:55:40Z", - "modified": "2026-08-17T17:14:34Z", + "modified": "2026-09-04T09:10:20Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-jiratui-CVE-2026-76221.json b/advisories/BREW-jiratui-CVE-2026-76221.json index 7d1abe58560..f23d52dc454 100644 --- a/advisories/BREW-jiratui-CVE-2026-76221.json +++ b/advisories/BREW-jiratui-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-jiratui-CVE-2026-76221", "published": "2026-08-20T09:04:13Z", - "modified": "2026-08-30T09:08:48Z", + "modified": "2026-09-04T09:15:06Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jiratui-CVE-2026-76222.json b/advisories/BREW-jiratui-CVE-2026-76222.json index 2de8b4dbc5c..6d6cc0f7f99 100644 --- a/advisories/BREW-jiratui-CVE-2026-76222.json +++ b/advisories/BREW-jiratui-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-jiratui-CVE-2026-76222", "published": "2026-08-20T09:04:13Z", - "modified": "2026-08-30T09:08:48Z", + "modified": "2026-09-04T09:15:06Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jiratui-CVE-2026-78675.json b/advisories/BREW-jiratui-CVE-2026-78675.json new file mode 100644 index 00000000000..a1b00e89ba0 --- /dev/null +++ b/advisories/BREW-jiratui-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-jiratui-CVE-2026-78675", + "published": "2026-09-04T09:16:19Z", + "modified": "2026-09-04T09:16:19Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "jiratui", + "purl": "pkg:brew/jiratui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-jiratui-CVE-2026-78676.json b/advisories/BREW-jiratui-CVE-2026-78676.json new file mode 100644 index 00000000000..5b2aa99937f --- /dev/null +++ b/advisories/BREW-jiratui-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-jiratui-CVE-2026-78676", + "published": "2026-09-04T09:16:19Z", + "modified": "2026-09-04T09:16:19Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "jiratui", + "purl": "pkg:brew/jiratui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-jiratui-CVE-2026-78677.json b/advisories/BREW-jiratui-CVE-2026-78677.json new file mode 100644 index 00000000000..6bed1d8f110 --- /dev/null +++ b/advisories/BREW-jiratui-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-jiratui-CVE-2026-78677", + "published": "2026-09-04T09:16:19Z", + "modified": "2026-09-04T09:16:19Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "jiratui", + "purl": "pkg:brew/jiratui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-jiratui-CVE-2026-78678.json b/advisories/BREW-jiratui-CVE-2026-78678.json new file mode 100644 index 00000000000..f5b6cde5760 --- /dev/null +++ b/advisories/BREW-jiratui-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-jiratui-CVE-2026-78678", + "published": "2026-09-04T09:16:19Z", + "modified": "2026-09-04T09:16:19Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "jiratui", + "purl": "pkg:brew/jiratui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.61" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-jiratui-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-jiratui-GHSA-hmq2-w58f-27jc.json index c89a478edec..9690f37b5b7 100644 --- a/advisories/BREW-jiratui-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-jiratui-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-jiratui-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:00:58Z", - "modified": "2026-08-30T09:08:48Z", + "modified": "2026-09-04T09:15:06Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-jiratui-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-jiratui-GHSA-jm78-9fvv-mhgr.json index 8a8051824df..88a6846ecc8 100644 --- a/advisories/BREW-jiratui-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-jiratui-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-jiratui-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:00:58Z", - "modified": "2026-08-30T09:08:48Z", + "modified": "2026-09-04T09:15:06Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.61", + "key": "pkg:pypi/gitpython@3.1.61", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-kimi-cli-CVE-2026-76221.json b/advisories/BREW-kimi-cli-CVE-2026-76221.json index d66f933eb81..ddd971171d0 100644 --- a/advisories/BREW-kimi-cli-CVE-2026-76221.json +++ b/advisories/BREW-kimi-cli-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-kimi-cli-CVE-2026-76221", "published": "2026-08-20T09:04:48Z", - "modified": "2026-08-20T09:04:48Z", + "modified": "2026-09-04T09:18:03Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-kimi-cli-CVE-2026-76222.json b/advisories/BREW-kimi-cli-CVE-2026-76222.json index a3e6536097c..8c7e03c5df8 100644 --- a/advisories/BREW-kimi-cli-CVE-2026-76222.json +++ b/advisories/BREW-kimi-cli-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-kimi-cli-CVE-2026-76222", "published": "2026-08-20T09:04:48Z", - "modified": "2026-08-20T09:04:48Z", + "modified": "2026-09-04T09:18:03Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-kimi-cli-CVE-2026-78675.json b/advisories/BREW-kimi-cli-CVE-2026-78675.json new file mode 100644 index 00000000000..fde5f7ee300 --- /dev/null +++ b/advisories/BREW-kimi-cli-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-kimi-cli-CVE-2026-78675", + "published": "2026-09-04T09:18:03Z", + "modified": "2026-09-04T09:18:03Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "kimi-cli", + "purl": "pkg:brew/kimi-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.52" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-kimi-cli-CVE-2026-78676.json b/advisories/BREW-kimi-cli-CVE-2026-78676.json new file mode 100644 index 00000000000..837319687b6 --- /dev/null +++ b/advisories/BREW-kimi-cli-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-kimi-cli-CVE-2026-78676", + "published": "2026-09-04T09:18:03Z", + "modified": "2026-09-04T09:18:03Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "kimi-cli", + "purl": "pkg:brew/kimi-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.52" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-kimi-cli-CVE-2026-78677.json b/advisories/BREW-kimi-cli-CVE-2026-78677.json new file mode 100644 index 00000000000..4488b0e6e58 --- /dev/null +++ b/advisories/BREW-kimi-cli-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-kimi-cli-CVE-2026-78677", + "published": "2026-09-04T09:18:03Z", + "modified": "2026-09-04T09:18:03Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "kimi-cli", + "purl": "pkg:brew/kimi-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.52" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-kimi-cli-CVE-2026-78678.json b/advisories/BREW-kimi-cli-CVE-2026-78678.json new file mode 100644 index 00000000000..1a9caae3b60 --- /dev/null +++ b/advisories/BREW-kimi-cli-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-kimi-cli-CVE-2026-78678", + "published": "2026-09-04T09:18:03Z", + "modified": "2026-09-04T09:18:03Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "kimi-cli", + "purl": "pkg:brew/kimi-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.52" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-kimi-cli-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-kimi-cli-GHSA-hmq2-w58f-27jc.json index 01ebe2f45e8..aa35b430bcc 100644 --- a/advisories/BREW-kimi-cli-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-kimi-cli-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-kimi-cli-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:01:40Z", - "modified": "2026-08-29T09:06:02Z", + "modified": "2026-09-04T09:18:03Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-kimi-cli-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-kimi-cli-GHSA-jm78-9fvv-mhgr.json index 288582f5c04..8c618020c2e 100644 --- a/advisories/BREW-kimi-cli-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-kimi-cli-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-kimi-cli-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:01:40Z", - "modified": "2026-08-29T09:06:02Z", + "modified": "2026-09-04T09:18:03Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.52", + "key": "pkg:pypi/gitpython@3.1.52", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-76221.json b/advisories/BREW-legit-CVE-2026-76221.json index a4e449a4cc4..1e472d83e80 100644 --- a/advisories/BREW-legit-CVE-2026-76221.json +++ b/advisories/BREW-legit-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76221", "published": "2026-08-20T09:05:37Z", - "modified": "2026-08-20T09:05:37Z", + "modified": "2026-09-04T09:19:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-76222.json b/advisories/BREW-legit-CVE-2026-76222.json index 08bdf96d492..a08ad4ef306 100644 --- a/advisories/BREW-legit-CVE-2026-76222.json +++ b/advisories/BREW-legit-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-CVE-2026-76222", "published": "2026-08-20T09:05:37Z", - "modified": "2026-08-20T09:05:37Z", + "modified": "2026-09-04T09:19:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-CVE-2026-78675.json b/advisories/BREW-legit-CVE-2026-78675.json new file mode 100644 index 00000000000..825005b1028 --- /dev/null +++ b/advisories/BREW-legit-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-legit-CVE-2026-78675", + "published": "2026-09-04T09:19:02Z", + "modified": "2026-09-04T09:19:02Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "legit", + "purl": "pkg:brew/legit" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-legit-CVE-2026-78676.json b/advisories/BREW-legit-CVE-2026-78676.json new file mode 100644 index 00000000000..7b25336e596 --- /dev/null +++ b/advisories/BREW-legit-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-legit-CVE-2026-78676", + "published": "2026-09-04T09:19:02Z", + "modified": "2026-09-04T09:19:02Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "legit", + "purl": "pkg:brew/legit" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-legit-CVE-2026-78677.json b/advisories/BREW-legit-CVE-2026-78677.json new file mode 100644 index 00000000000..604139d89b2 --- /dev/null +++ b/advisories/BREW-legit-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-legit-CVE-2026-78677", + "published": "2026-09-04T09:19:02Z", + "modified": "2026-09-04T09:19:02Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "legit", + "purl": "pkg:brew/legit" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-legit-CVE-2026-78678.json b/advisories/BREW-legit-CVE-2026-78678.json new file mode 100644 index 00000000000..2a568332ba4 --- /dev/null +++ b/advisories/BREW-legit-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-legit-CVE-2026-78678", + "published": "2026-09-04T09:19:02Z", + "modified": "2026-09-04T09:19:02Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "legit", + "purl": "pkg:brew/legit" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-legit-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-legit-GHSA-hmq2-w58f-27jc.json index ef12dc92697..9d0a9ed313c 100644 --- a/advisories/BREW-legit-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-legit-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:02:43Z", - "modified": "2026-08-29T09:06:59Z", + "modified": "2026-09-04T09:19:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-legit-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-legit-GHSA-jm78-9fvv-mhgr.json index 64f921c08dc..5a2efdd2c28 100644 --- a/advisories/BREW-legit-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-legit-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-legit-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:02:43Z", - "modified": "2026-08-29T09:06:59Z", + "modified": "2026-09-04T09:19:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-llm-CVE-2026-31236.json b/advisories/BREW-llm-CVE-2026-31236.json index 8f426e700bb..d1e30ea311f 100644 --- a/advisories/BREW-llm-CVE-2026-31236.json +++ b/advisories/BREW-llm-CVE-2026-31236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-llm-CVE-2026-31236", "published": "2026-08-13T17:03:00Z", - "modified": "2026-09-03T09:21:28Z", + "modified": "2026-09-04T09:19:21Z", "upstream": [ "GHSA-g76p-4vg5-f4qh", "CVE-2026-31236", @@ -43,15 +43,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "llm", - "subject_version": "0.33", - "key": "pkg:pypi/llm@0.33" + "subject_version": "0.34", + "key": "pkg:pypi/llm@0.34" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "llm", - "subject_version": "0.33", - "key": "pkg:pypi/llm@0.33" + "subject_version": "0.34", + "key": "pkg:pypi/llm@0.34" } ] }, diff --git a/advisories/BREW-llm-CVE-2026-7246.json b/advisories/BREW-llm-CVE-2026-7246.json index f1b35be0451..ab08d3af75c 100644 --- a/advisories/BREW-llm-CVE-2026-7246.json +++ b/advisories/BREW-llm-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-llm-CVE-2026-7246", "published": "2026-08-13T17:03:00Z", - "modified": "2026-08-13T17:03:00Z", + "modified": "2026-09-04T09:19:21Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.4.2" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.4.2", - "key": "pkg:pypi/click@8.4.2", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2009-3287.json b/advisories/BREW-mailcatcher-CVE-2009-3287.json index 31566b29b69..2c2b6f167aa 100644 --- a/advisories/BREW-mailcatcher-CVE-2009-3287.json +++ b/advisories/BREW-mailcatcher-CVE-2009-3287.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2009-3287", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-j24p-r6wx-r79w", "CVE-2009-3287" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.2.4", "resource": "thin", - "resource_purl": "pkg:gem/thin@1.8.2" + "resource_purl": "pkg:gem/thin@2.0.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "thin", - "subject_version": "1.8.2", - "key": "pkg:gem/thin@1.8.2", + "subject_version": "2.0.1", + "key": "pkg:gem/thin@2.0.1", "resource": "thin" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2011-0739.json b/advisories/BREW-mailcatcher-CVE-2011-0739.json index de45daa13bf..ab59126c382 100644 --- a/advisories/BREW-mailcatcher-CVE-2011-0739.json +++ b/advisories/BREW-mailcatcher-CVE-2011-0739.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2011-0739", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-cpjc-p7fc-j9xh", "CVE-2011-0739" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.15", "resource": "mail", - "resource_purl": "pkg:gem/mail@2.8.1" + "resource_purl": "pkg:gem/mail@2.9.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "mail", - "subject_version": "2.8.1", - "key": "pkg:gem/mail@2.8.1", + "subject_version": "2.9.1", + "key": "pkg:gem/mail@2.9.1", "resource": "mail" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2011-5036.json b/advisories/BREW-mailcatcher-CVE-2011-5036.json index 3bebe7466d5..aa0944ddcf3 100644 --- a/advisories/BREW-mailcatcher-CVE-2011-5036.json +++ b/advisories/BREW-mailcatcher-CVE-2011-5036.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2011-5036", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-v6j3-7jrw-hq2p", "CVE-2011-5036" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.3.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2012-2139.json b/advisories/BREW-mailcatcher-CVE-2012-2139.json index 31250d5d634..50fee3c33f3 100644 --- a/advisories/BREW-mailcatcher-CVE-2012-2139.json +++ b/advisories/BREW-mailcatcher-CVE-2012-2139.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2012-2139", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-cj92-c4fj-w9c5", "CVE-2012-2139" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.4.4", "resource": "mail", - "resource_purl": "pkg:gem/mail@2.8.1" + "resource_purl": "pkg:gem/mail@2.9.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "mail", - "subject_version": "2.8.1", - "key": "pkg:gem/mail@2.8.1", + "subject_version": "2.9.1", + "key": "pkg:gem/mail@2.9.1", "resource": "mail" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2012-2140.json b/advisories/BREW-mailcatcher-CVE-2012-2140.json index 2eb241cda6d..97229c15b6d 100644 --- a/advisories/BREW-mailcatcher-CVE-2012-2140.json +++ b/advisories/BREW-mailcatcher-CVE-2012-2140.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2012-2140", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-rp63-jfmw-532w", "CVE-2012-2140" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.4.3", "resource": "mail", - "resource_purl": "pkg:gem/mail@2.8.1" + "resource_purl": "pkg:gem/mail@2.9.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "mail", - "subject_version": "2.8.1", - "key": "pkg:gem/mail@2.8.1", + "subject_version": "2.9.1", + "key": "pkg:gem/mail@2.9.1", "resource": "mail" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2012-6109.json b/advisories/BREW-mailcatcher-CVE-2012-6109.json index 9e4a03303fa..c73cdda2ede 100644 --- a/advisories/BREW-mailcatcher-CVE-2012-6109.json +++ b/advisories/BREW-mailcatcher-CVE-2012-6109.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2012-6109", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-h77x-m5q8-c29h", "CVE-2012-6109" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.4.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2013-0183.json b/advisories/BREW-mailcatcher-CVE-2013-0183.json index 3bb47538770..672b460a981 100644 --- a/advisories/BREW-mailcatcher-CVE-2013-0183.json +++ b/advisories/BREW-mailcatcher-CVE-2013-0183.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2013-0183", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:20Z", "upstream": [ "GHSA-3pxh-h8hw-mj8w", "CVE-2013-0183" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.4.3", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2013-0184.json b/advisories/BREW-mailcatcher-CVE-2013-0184.json index a9866d28987..51b61ee71b2 100644 --- a/advisories/BREW-mailcatcher-CVE-2013-0184.json +++ b/advisories/BREW-mailcatcher-CVE-2013-0184.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2013-0184", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-v882-ccj6-jc48", "CVE-2013-0184" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.4.4", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2013-0262.json b/advisories/BREW-mailcatcher-CVE-2013-0262.json index ac742ec52b7..b09177d8bcf 100644 --- a/advisories/BREW-mailcatcher-CVE-2013-0262.json +++ b/advisories/BREW-mailcatcher-CVE-2013-0262.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2013-0262", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-85r7-w5mv-c849", "CVE-2013-0262" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2013-0263.json b/advisories/BREW-mailcatcher-CVE-2013-0263.json index 8c5605d4f27..524a09e0bf3 100644 --- a/advisories/BREW-mailcatcher-CVE-2013-0263.json +++ b/advisories/BREW-mailcatcher-CVE-2013-0263.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2013-0263", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-xc85-32mf-xpv8", "CVE-2013-0263" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2015-3225.json b/advisories/BREW-mailcatcher-CVE-2015-3225.json index a990f3f8518..ca460f970f5 100644 --- a/advisories/BREW-mailcatcher-CVE-2015-3225.json +++ b/advisories/BREW-mailcatcher-CVE-2015-3225.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2015-3225", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-rgr4-9jh5-j4j6", "CVE-2015-3225" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.6.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2015-9097.json b/advisories/BREW-mailcatcher-CVE-2015-9097.json index abfdbc19ee5..41685ecee51 100644 --- a/advisories/BREW-mailcatcher-CVE-2015-9097.json +++ b/advisories/BREW-mailcatcher-CVE-2015-9097.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2015-9097", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-q86f-fmqf-qrf6", "CVE-2015-9097" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.5.5", "resource": "mail", - "resource_purl": "pkg:gem/mail@2.8.1" + "resource_purl": "pkg:gem/mail@2.9.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "mail", - "subject_version": "2.8.1", - "key": "pkg:gem/mail@2.8.1", + "subject_version": "2.9.1", + "key": "pkg:gem/mail@2.9.1", "resource": "mail" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2018-1000119.json b/advisories/BREW-mailcatcher-CVE-2018-1000119.json index afa40523190..d05f6e23d8c 100644 --- a/advisories/BREW-mailcatcher-CVE-2018-1000119.json +++ b/advisories/BREW-mailcatcher-CVE-2018-1000119.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2018-1000119", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-688c-3x49-6rqj", "CVE-2018-1000119" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.0", "resource": "rack-protection", - "resource_purl": "pkg:gem/rack-protection@3.2.0" + "resource_purl": "pkg:gem/rack-protection@4.2.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack-protection", - "subject_version": "3.2.0", - "key": "pkg:gem/rack-protection@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/rack-protection@4.2.1", "resource": "rack-protection" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2018-11627.json b/advisories/BREW-mailcatcher-CVE-2018-11627.json index 007406e59af..efb287579f0 100644 --- a/advisories/BREW-mailcatcher-CVE-2018-11627.json +++ b/advisories/BREW-mailcatcher-CVE-2018-11627.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2018-11627", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-mq35-wqvf-r23c", "CVE-2018-11627" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.2", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2018-16470.json b/advisories/BREW-mailcatcher-CVE-2018-16470.json index 25cc8a1028f..c31161c4bda 100644 --- a/advisories/BREW-mailcatcher-CVE-2018-16470.json +++ b/advisories/BREW-mailcatcher-CVE-2018-16470.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2018-16470", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-hg78-4f6x-99wq", "CVE-2018-16470" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2018-16471.json b/advisories/BREW-mailcatcher-CVE-2018-16471.json index 95b49620d9f..9396cd492a9 100644 --- a/advisories/BREW-mailcatcher-CVE-2018-16471.json +++ b/advisories/BREW-mailcatcher-CVE-2018-16471.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2018-16471", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-5r2p-j47h-mhpg", "CVE-2018-16471" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2018-7212.json b/advisories/BREW-mailcatcher-CVE-2018-7212.json index b2545a7ba57..267dc2304ef 100644 --- a/advisories/BREW-mailcatcher-CVE-2018-7212.json +++ b/advisories/BREW-mailcatcher-CVE-2018-7212.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2018-7212", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-h29f-7f56-j8wh", "CVE-2018-7212" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.1", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2019-16782.json b/advisories/BREW-mailcatcher-CVE-2019-16782.json index d80923bff64..5035f4adf8a 100644 --- a/advisories/BREW-mailcatcher-CVE-2019-16782.json +++ b/advisories/BREW-mailcatcher-CVE-2019-16782.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2019-16782", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-hrqr-hxpp-chr3", "CVE-2019-16782" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.0.8", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2020-15133.json b/advisories/BREW-mailcatcher-CVE-2020-15133.json index ebe4e29d469..ab6493587f9 100644 --- a/advisories/BREW-mailcatcher-CVE-2020-15133.json +++ b/advisories/BREW-mailcatcher-CVE-2020-15133.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2020-15133", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-2v5c-755p-p4gv", "CVE-2020-15133" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.11.0", "resource": "faye-websocket", - "resource_purl": "pkg:gem/faye-websocket@0.11.3" + "resource_purl": "pkg:gem/faye-websocket@0.12.0" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "faye-websocket", - "subject_version": "0.11.3", - "key": "pkg:gem/faye-websocket@0.11.3", + "subject_version": "0.12.0", + "key": "pkg:gem/faye-websocket@0.12.0", "resource": "faye-websocket" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2020-8161.json b/advisories/BREW-mailcatcher-CVE-2020-8161.json index ecdc4fadff5..c1f8da3ade3 100644 --- a/advisories/BREW-mailcatcher-CVE-2020-8161.json +++ b/advisories/BREW-mailcatcher-CVE-2020-8161.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2020-8161", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-5f9h-9pjv-v6j7", "CVE-2020-8161" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.1.3", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2020-8184.json b/advisories/BREW-mailcatcher-CVE-2020-8184.json index b81541c2f46..eec81888490 100644 --- a/advisories/BREW-mailcatcher-CVE-2020-8184.json +++ b/advisories/BREW-mailcatcher-CVE-2020-8184.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2020-8184", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-j6w9-fv6q-3q52", "CVE-2020-8184" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.3", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2021-41817.json b/advisories/BREW-mailcatcher-CVE-2021-41817.json index 4f6d9f66e8d..bdc44d6559f 100644 --- a/advisories/BREW-mailcatcher-CVE-2021-41817.json +++ b/advisories/BREW-mailcatcher-CVE-2021-41817.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2021-41817", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-qg54-694p-wgpp", "BIT-ruby-2021-41817", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.2.1", "resource": "date", - "resource_purl": "pkg:gem/date@3.3.4" + "resource_purl": "pkg:gem/date@3.5.1" } } ], @@ -47,8 +47,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "date", - "subject_version": "3.3.4", - "key": "pkg:gem/date@3.3.4", + "subject_version": "3.5.1", + "key": "pkg:gem/date@3.5.1", "resource": "date" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-29970.json b/advisories/BREW-mailcatcher-CVE-2022-29970.json index f625100b4e7..51b619a49eb 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-29970.json +++ b/advisories/BREW-mailcatcher-CVE-2022-29970.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-29970", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-qp49-3pvw-x4m5", "CVE-2022-29970" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.0", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-30122.json b/advisories/BREW-mailcatcher-CVE-2022-30122.json index 69c1a6a9ef3..6ca04e4c2e6 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-30122.json +++ b/advisories/BREW-mailcatcher-CVE-2022-30122.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-30122", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-hxqx-xwvh-44m2", "CVE-2022-30122" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.3.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-30123.json b/advisories/BREW-mailcatcher-CVE-2022-30123.json index 57d4b97e71e..b5199404c3e 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-30123.json +++ b/advisories/BREW-mailcatcher-CVE-2022-30123.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-30123", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-wq4h-7r42-5hrr", "CVE-2022-30123" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.3.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-44570.json b/advisories/BREW-mailcatcher-CVE-2022-44570.json index 9ce012ab35d..b2ba942f3dd 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-44570.json +++ b/advisories/BREW-mailcatcher-CVE-2022-44570.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-44570", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-65f5-mfpf-vfhj", "CVE-2022-44570" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.6.2", + "upstream_fixed_in": "3.0.4.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-44571.json b/advisories/BREW-mailcatcher-CVE-2022-44571.json index 8bfd4567978..d869dde0939 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-44571.json +++ b/advisories/BREW-mailcatcher-CVE-2022-44571.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-44571", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-93pm-5p5f-3ghx", "CVE-2022-44571" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.6.1", + "upstream_fixed_in": "3.0.4.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-44572.json b/advisories/BREW-mailcatcher-CVE-2022-44572.json index eed157b7a70..b2e2b25d7cf 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-44572.json +++ b/advisories/BREW-mailcatcher-CVE-2022-44572.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-44572", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-rqv2-275x-2jq5", "CVE-2022-44572" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.6.1", + "upstream_fixed_in": "3.0.4.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2022-45442.json b/advisories/BREW-mailcatcher-CVE-2022-45442.json index a3f5404952a..1ccba08d34f 100644 --- a/advisories/BREW-mailcatcher-CVE-2022-45442.json +++ b/advisories/BREW-mailcatcher-CVE-2022-45442.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2022-45442", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-2x8x-jmrp-phxw", "CVE-2022-45442" @@ -32,7 +32,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.0.4", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2023-27530.json b/advisories/BREW-mailcatcher-CVE-2023-27530.json index c1485122c03..b439b84015b 100644 --- a/advisories/BREW-mailcatcher-CVE-2023-27530.json +++ b/advisories/BREW-mailcatcher-CVE-2023-27530.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2023-27530", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:20Z", "upstream": [ "GHSA-3h57-hmj3-gj3p", "CVE-2023-27530" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.6.3", + "upstream_fixed_in": "3.0.4.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2023-27539.json b/advisories/BREW-mailcatcher-CVE-2023-27539.json index 5a46162532b..555729c3c3f 100644 --- a/advisories/BREW-mailcatcher-CVE-2023-27539.json +++ b/advisories/BREW-mailcatcher-CVE-2023-27539.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2023-27539", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-c6qg-cjj8-47qp", "CVE-2023-27539" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.6.4", + "upstream_fixed_in": "3.0.6.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2024-21510.json b/advisories/BREW-mailcatcher-CVE-2024-21510.json index 3f98c7477ee..3c0970d72ab 100644 --- a/advisories/BREW-mailcatcher-CVE-2024-21510.json +++ b/advisories/BREW-mailcatcher-CVE-2024-21510.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2024-21510", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-hxx2-7vcw-mqr3", "CVE-2024-21510" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "4.1.0", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2024-25126.json b/advisories/BREW-mailcatcher-CVE-2024-25126.json index 1349cc8fa96..ab97842a972 100644 --- a/advisories/BREW-mailcatcher-CVE-2024-25126.json +++ b/advisories/BREW-mailcatcher-CVE-2024-25126.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2024-25126", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:20Z", "upstream": [ "GHSA-22f2-v57c-j9cx", "CVE-2024-25126" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.8.1", + "upstream_fixed_in": "3.0.9.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2024-26141.json b/advisories/BREW-mailcatcher-CVE-2024-26141.json index 8288e04032a..a5bbfef3077 100644 --- a/advisories/BREW-mailcatcher-CVE-2024-26141.json +++ b/advisories/BREW-mailcatcher-CVE-2024-26141.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2024-26141", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-xj5v-6v4g-jfw6", "CVE-2024-26141" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.8.1", + "upstream_fixed_in": "3.0.9.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2024-26146.json b/advisories/BREW-mailcatcher-CVE-2024-26146.json index 43835d5bacc..0993edeee56 100644 --- a/advisories/BREW-mailcatcher-CVE-2024-26146.json +++ b/advisories/BREW-mailcatcher-CVE-2024-26146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2024-26146", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-54rr-7fvw-6x8f", "CVE-2024-26146" @@ -30,9 +30,9 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.2.8.1", + "upstream_fixed_in": "3.0.9.1", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -45,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-25184.json b/advisories/BREW-mailcatcher-CVE-2025-25184.json index 3bd4f649e1d..57ec3157d8b 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-25184.json +++ b/advisories/BREW-mailcatcher-CVE-2025-25184.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-25184", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-7g2v-jj9q-g3rg", "CVE-2025-25184" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.11", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.10", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-25186.json b/advisories/BREW-mailcatcher-CVE-2025-25186.json index 54b01de0a4d..ab0e4504739 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-25186.json +++ b/advisories/BREW-mailcatcher-CVE-2025-25186.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-25186", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-7fc5-f82f-cx69", "CVE-2025-25186" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.19", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.5.6", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-27111.json b/advisories/BREW-mailcatcher-CVE-2025-27111.json index 780a0d58a0d..737c43bc257 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-27111.json +++ b/advisories/BREW-mailcatcher-CVE-2025-27111.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-27111", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-8cgq-6mh2-7j6v", "CVE-2025-27111" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.12", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.11", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-27610.json b/advisories/BREW-mailcatcher-CVE-2025-27610.json index 937c53930f0..1e8aa3e0ed3 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-27610.json +++ b/advisories/BREW-mailcatcher-CVE-2025-27610.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-27610", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-7wqh-767x-r66v", "CVE-2025-27610" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.13", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.12", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-32441.json b/advisories/BREW-mailcatcher-CVE-2025-32441.json index 8194d004342..f4182aaa6cc 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-32441.json +++ b/advisories/BREW-mailcatcher-CVE-2025-32441.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-32441", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-vpfw-47h7-xj4g", "CVE-2025-32441" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "2.2.14", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-43857.json b/advisories/BREW-mailcatcher-CVE-2025-43857.json index 4e3ed9a37dc..a18dfebda24 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-43857.json +++ b/advisories/BREW-mailcatcher-CVE-2025-43857.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-43857", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-j3g3-5qv5-52mj", "CVE-2025-43857" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.20", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.5.7", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-46727.json b/advisories/BREW-mailcatcher-CVE-2025-46727.json index 5363c0325d9..0d49a263a33 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-46727.json +++ b/advisories/BREW-mailcatcher-CVE-2025-46727.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-46727", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-gjh7-p2fx-99vx", "CVE-2025-46727" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.14", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.14", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-59830.json b/advisories/BREW-mailcatcher-CVE-2025-59830.json index 504eb102744..939f02bf787 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-59830.json +++ b/advisories/BREW-mailcatcher-CVE-2025-59830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-59830", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-625h-95r8-8xpm", "CVE-2025-59830" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "2.2.18", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61770.json b/advisories/BREW-mailcatcher-CVE-2025-61770.json index 88293d25ce9..a37bb28022a 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61770.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61770.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61770", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-p543-xpfm-54cp", "CVE-2025-61770" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.19", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61771.json b/advisories/BREW-mailcatcher-CVE-2025-61771.json index c03cf1d6eab..b4888ea8b19 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61771.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61771.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61771", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-w9pc-fmgc-vxvw", "CVE-2025-61771" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.19", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61772.json b/advisories/BREW-mailcatcher-CVE-2025-61772.json index e2ef26c575a..ece0f159cc9 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61772.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61772.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61772", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-wpv5-97wm-hp9c", "CVE-2025-61772" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.19", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.2", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61780.json b/advisories/BREW-mailcatcher-CVE-2025-61780.json index bd3ad19d79d..ed7cd568e48 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61780.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61780.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61780", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-r657-rxjc-j557", "CVE-2025-61780" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.20", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.3", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61919.json b/advisories/BREW-mailcatcher-CVE-2025-61919.json index 26546bca21f..af6d090b786 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61919.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61919.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61919", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-6xw4-3v39-52mm", "CVE-2025-61919" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.20", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.3", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2025-61921.json b/advisories/BREW-mailcatcher-CVE-2025-61921.json index 553cff25d86..28a6a0a2d49 100644 --- a/advisories/BREW-mailcatcher-CVE-2025-61921.json +++ b/advisories/BREW-mailcatcher-CVE-2025-61921.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2025-61921", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-mr3q-g2mv-mr4q", "CVE-2025-61921" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "4.2.0", "resource": "sinatra", - "resource_purl": "pkg:gem/sinatra@3.2.0" + "resource_purl": "pkg:gem/sinatra@4.2.1" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sinatra", - "subject_version": "3.2.0", - "key": "pkg:gem/sinatra@3.2.0", + "subject_version": "4.2.1", + "key": "pkg:gem/sinatra@4.2.1", "resource": "sinatra" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-22860.json b/advisories/BREW-mailcatcher-CVE-2026-22860.json index 09f38e430a0..df3fa541464 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-22860.json +++ b/advisories/BREW-mailcatcher-CVE-2026-22860.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-22860", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-mxw3-3hh2-x2mh", "CVE-2026-22860" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.22", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.5", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-25500.json b/advisories/BREW-mailcatcher-CVE-2026-25500.json index 1d4e3e9df1f..de7b6ef3cbb 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-25500.json +++ b/advisories/BREW-mailcatcher-CVE-2026-25500.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-25500", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-whrj-4476-wvmp", "CVE-2026-25500" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.22", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.5", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-26961.json b/advisories/BREW-mailcatcher-CVE-2026-26961.json index c8657ca95b5..ebfe45cd4aa 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-26961.json +++ b/advisories/BREW-mailcatcher-CVE-2026-26961.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-26961", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-vgpv-f759-9wx3", "CVE-2026-26961" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34230.json b/advisories/BREW-mailcatcher-CVE-2026-34230.json index c870c42de3d..0527d5f2262 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34230.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34230", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-v569-hp3g-36wr", "CVE-2026-34230" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34763.json b/advisories/BREW-mailcatcher-CVE-2026-34763.json index a2b19080a3b..50b22e145e1 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34763.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34763.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34763", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-7mqq-6cf9-v2qp", "CVE-2026-34763" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34785.json b/advisories/BREW-mailcatcher-CVE-2026-34785.json index 3533b1b9df4..45aab98b0fe 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34785.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34785.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34785", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-h2jq-g4cq-5ppq", "CVE-2026-34785" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34786.json b/advisories/BREW-mailcatcher-CVE-2026-34786.json index 76d33ecc412..5769ea022d6 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34786.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34786.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34786", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-q4qf-9j86-f5mh", "CVE-2026-34786" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34826.json b/advisories/BREW-mailcatcher-CVE-2026-34826.json index 496f15a266c..799d17a2b37 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34826.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34826.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34826", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-x8cg-fq8g-mxfx", "CVE-2026-34826" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34829.json b/advisories/BREW-mailcatcher-CVE-2026-34829.json index 2a2682354a2..1d9317b9c98 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34829.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34829.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34829", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-8vqr-qjwx-82mw", "CVE-2026-34829" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34830.json b/advisories/BREW-mailcatcher-CVE-2026-34830.json index 5da5e665b75..6474a8a348a 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34830.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34830.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34830", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-qv7j-4883-hwh7", "CVE-2026-34830" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-34831.json b/advisories/BREW-mailcatcher-CVE-2026-34831.json index 7bb4a5556d3..56de5c5a2c0 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-34831.json +++ b/advisories/BREW-mailcatcher-CVE-2026-34831.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-34831", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-q2ww-5357-x388", "CVE-2026-34831" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "2.2.23", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.2.6", "resource": "rack", - "resource_purl": "pkg:gem/rack@2.2.9" + "resource_purl": "pkg:gem/rack@3.2.7" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "rack", - "subject_version": "2.2.9", - "key": "pkg:gem/rack@2.2.9", + "subject_version": "3.2.7", + "key": "pkg:gem/rack@3.2.7", "resource": "rack" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-42245.json b/advisories/BREW-mailcatcher-CVE-2026-42245.json index f24b408a7dd..986c9e0d038 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-42245.json +++ b/advisories/BREW-mailcatcher-CVE-2026-42245.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-42245", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-q2mw-fvj9-vvcw", "CVE-2026-42245" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.24", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-42246.json b/advisories/BREW-mailcatcher-CVE-2026-42246.json index 2abff3341bc..e0cd53ab9ba 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-42246.json +++ b/advisories/BREW-mailcatcher-CVE-2026-42246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-42246", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-vcgp-9326-pqcp", "CVE-2026-42246" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.24", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-42256.json b/advisories/BREW-mailcatcher-CVE-2026-42256.json index be72241217f..f8720cd1775 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-42256.json +++ b/advisories/BREW-mailcatcher-CVE-2026-42256.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-42256", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-87pf-fpwv-p7m7", "CVE-2026-42256" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.24", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-42257.json b/advisories/BREW-mailcatcher-CVE-2026-42257.json index af36cb02139..2196b649b03 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-42257.json +++ b/advisories/BREW-mailcatcher-CVE-2026-42257.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-42257", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-hm49-wcqc-g2xg", "CVE-2026-42257" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.24", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-42258.json b/advisories/BREW-mailcatcher-CVE-2026-42258.json index ca52d6ee4ec..d7ab297468c 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-42258.json +++ b/advisories/BREW-mailcatcher-CVE-2026-42258.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-42258", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-75xq-5h9v-w6px", "CVE-2026-42258" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.4.24", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-47240.json b/advisories/BREW-mailcatcher-CVE-2026-47240.json index 8227b132eeb..83d4eb211cf 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-47240.json +++ b/advisories/BREW-mailcatcher-CVE-2026-47240.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-47240", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-8p34-64r3-mwg8", "CVE-2026-47240" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.5.15", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4.1", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-47241.json b/advisories/BREW-mailcatcher-CVE-2026-47241.json index 8cd84084da3..2cef2cd8df5 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-47241.json +++ b/advisories/BREW-mailcatcher-CVE-2026-47241.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-47241", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-c4fp-cxrr-mj66", "CVE-2026-47241" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.5.15", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4.1", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-47242.json b/advisories/BREW-mailcatcher-CVE-2026-47242.json index 85416ec2dca..08e9e1df986 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-47242.json +++ b/advisories/BREW-mailcatcher-CVE-2026-47242.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-47242", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-46q3-7gv7-qmgg", "CVE-2026-47242" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", - "upstream_fixed_in": "0.5.15", + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "0.6.4.1", "resource": "net-imap", - "resource_purl": "pkg:gem/net-imap@0.4.9.1" + "resource_purl": "pkg:gem/net-imap@0.6.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "net-imap", - "subject_version": "0.4.9.1", - "key": "pkg:gem/net-imap@0.4.9.1", + "subject_version": "0.6.6", + "key": "pkg:gem/net-imap@0.6.6", "resource": "net-imap" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-54463.json b/advisories/BREW-mailcatcher-CVE-2026-54463.json index 1e73556fe1d..dc3742b2bef 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-54463.json +++ b/advisories/BREW-mailcatcher-CVE-2026-54463.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-54463", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-17T17:29:14Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-ghhp-3qvg-889p", "CVE-2026-54463" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.8.1", "resource": "websocket-driver", - "resource_purl": "pkg:gem/websocket-driver@0.7.6" + "resource_purl": "pkg:gem/websocket-driver@0.8.2" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "websocket-driver", - "subject_version": "0.7.6", - "key": "pkg:gem/websocket-driver@0.7.6", + "subject_version": "0.8.2", + "key": "pkg:gem/websocket-driver@0.8.2", "resource": "websocket-driver" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-54464.json b/advisories/BREW-mailcatcher-CVE-2026-54464.json index 660f531caa0..5cfb29a265a 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-54464.json +++ b/advisories/BREW-mailcatcher-CVE-2026-54464.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-54464", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-17T17:29:14Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-33ph-fccm-39pj", "CVE-2026-54464" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.8.1", "resource": "websocket-driver", - "resource_purl": "pkg:gem/websocket-driver@0.7.6" + "resource_purl": "pkg:gem/websocket-driver@0.8.2" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "websocket-driver", - "subject_version": "0.7.6", - "key": "pkg:gem/websocket-driver@0.7.6", + "subject_version": "0.8.2", + "key": "pkg:gem/websocket-driver@0.8.2", "resource": "websocket-driver" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-54465.json b/advisories/BREW-mailcatcher-CVE-2026-54465.json index ee15ec9a4d9..ed962ef3a05 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-54465.json +++ b/advisories/BREW-mailcatcher-CVE-2026-54465.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-54465", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-17T17:29:14Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-8j3g-f24p-4mpw", "CVE-2026-54465" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.8.1", "resource": "websocket-driver", - "resource_purl": "pkg:gem/websocket-driver@0.7.6" + "resource_purl": "pkg:gem/websocket-driver@0.8.2" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "websocket-driver", - "subject_version": "0.7.6", - "key": "pkg:gem/websocket-driver@0.7.6", + "subject_version": "0.8.2", + "key": "pkg:gem/websocket-driver@0.8.2", "resource": "websocket-driver" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-54619.json b/advisories/BREW-mailcatcher-CVE-2026-54619.json index caba4b46b3b..3f02ad2c6c9 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-54619.json +++ b/advisories/BREW-mailcatcher-CVE-2026-54619.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-54619", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-28hh-pr2h-2w89", "CVE-2026-54619" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "2.9.5", "resource": "sqlite", - "resource_purl": "pkg:gem/sqlite3@1.7.3" + "resource_purl": "pkg:gem/sqlite3@2.9.6" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sqlite3", - "subject_version": "1.7.3", - "key": "pkg:gem/sqlite3@1.7.3", + "subject_version": "2.9.6", + "key": "pkg:gem/sqlite3@2.9.6", "resource": "sqlite" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-61666.json b/advisories/BREW-mailcatcher-CVE-2026-61666.json index 140df28d881..1604f7e0d24 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-61666.json +++ b/advisories/BREW-mailcatcher-CVE-2026-61666.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-61666", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-2x63-gw47-w4mm", "CVE-2026-61666" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.8.2", "resource": "websocket-driver", - "resource_purl": "pkg:gem/websocket-driver@0.7.6" + "resource_purl": "pkg:gem/websocket-driver@0.8.2" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "websocket-driver", - "subject_version": "0.7.6", - "key": "pkg:gem/websocket-driver@0.7.6", + "subject_version": "0.8.2", + "key": "pkg:gem/websocket-driver@0.8.2", "resource": "websocket-driver" } ] diff --git a/advisories/BREW-mailcatcher-CVE-2026-63435.json b/advisories/BREW-mailcatcher-CVE-2026-63435.json index 10024426f6c..4b99a4f870d 100644 --- a/advisories/BREW-mailcatcher-CVE-2026-63435.json +++ b/advisories/BREW-mailcatcher-CVE-2026-63435.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-CVE-2026-63435", "published": "2026-09-03T09:29:48Z", - "modified": "2026-09-03T09:29:48Z", + "modified": "2026-09-04T09:28:54Z", "upstream": [ "GHSA-mvxr-6m87-mv2q", "CVE-2026-63435" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "0.11.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "2.9.1", "resource": "mail", - "resource_purl": "pkg:gem/mail@2.8.1" + "resource_purl": "pkg:gem/mail@2.9.1" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "mail", - "subject_version": "2.8.1", - "key": "pkg:gem/mail@2.8.1", + "subject_version": "2.9.1", + "key": "pkg:gem/mail@2.9.1", "resource": "mail" } ] diff --git a/advisories/BREW-mailcatcher-GHSA-mgvv-5mxp-xq67.json b/advisories/BREW-mailcatcher-GHSA-mgvv-5mxp-xq67.json index 59c3d7ff469..0bdf6f1f4c7 100644 --- a/advisories/BREW-mailcatcher-GHSA-mgvv-5mxp-xq67.json +++ b/advisories/BREW-mailcatcher-GHSA-mgvv-5mxp-xq67.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mailcatcher-GHSA-mgvv-5mxp-xq67", "published": "2026-08-13T17:11:30Z", - "modified": "2026-08-13T17:11:30Z", + "modified": "2026-09-04T09:28:51Z", "upstream": [ "GHSA-mgvv-5mxp-xq67" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.1", "resource": "sqlite", - "resource_purl": "pkg:gem/sqlite3@1.7.3" + "resource_purl": "pkg:gem/sqlite3@2.9.6" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "RubyGems", "name": "sqlite3", - "subject_version": "1.7.3", - "key": "pkg:gem/sqlite3@1.7.3", + "subject_version": "2.9.6", + "key": "pkg:gem/sqlite3@2.9.6", "resource": "sqlite" } ] diff --git a/advisories/BREW-mentat-CVE-2026-76221.json b/advisories/BREW-mentat-CVE-2026-76221.json index ee84f7472c2..d378307fa34 100644 --- a/advisories/BREW-mentat-CVE-2026-76221.json +++ b/advisories/BREW-mentat-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mentat-CVE-2026-76221", "published": "2026-08-20T09:16:35Z", - "modified": "2026-08-20T09:16:35Z", + "modified": "2026-09-04T09:30:36Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mentat-CVE-2026-76222.json b/advisories/BREW-mentat-CVE-2026-76222.json index 9b1ca0ba2ef..bf5d8b7ce4f 100644 --- a/advisories/BREW-mentat-CVE-2026-76222.json +++ b/advisories/BREW-mentat-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mentat-CVE-2026-76222", "published": "2026-08-20T09:16:35Z", - "modified": "2026-08-20T09:16:35Z", + "modified": "2026-09-04T09:30:36Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mentat-CVE-2026-78675.json b/advisories/BREW-mentat-CVE-2026-78675.json new file mode 100644 index 00000000000..f371430dd4b --- /dev/null +++ b/advisories/BREW-mentat-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mentat-CVE-2026-78675", + "published": "2026-09-04T09:30:36Z", + "modified": "2026-09-04T09:30:36Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mentat", + "purl": "pkg:brew/mentat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.37" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-mentat-CVE-2026-78676.json b/advisories/BREW-mentat-CVE-2026-78676.json new file mode 100644 index 00000000000..f573662f4b6 --- /dev/null +++ b/advisories/BREW-mentat-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mentat-CVE-2026-78676", + "published": "2026-09-04T09:30:36Z", + "modified": "2026-09-04T09:30:36Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mentat", + "purl": "pkg:brew/mentat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.37" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-mentat-CVE-2026-78677.json b/advisories/BREW-mentat-CVE-2026-78677.json new file mode 100644 index 00000000000..ca64c3dba4d --- /dev/null +++ b/advisories/BREW-mentat-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mentat-CVE-2026-78677", + "published": "2026-09-04T09:30:36Z", + "modified": "2026-09-04T09:30:36Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mentat", + "purl": "pkg:brew/mentat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.37" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-mentat-CVE-2026-78678.json b/advisories/BREW-mentat-CVE-2026-78678.json new file mode 100644 index 00000000000..d8a8ad18525 --- /dev/null +++ b/advisories/BREW-mentat-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mentat-CVE-2026-78678", + "published": "2026-09-04T09:30:36Z", + "modified": "2026-09-04T09:30:36Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mentat", + "purl": "pkg:brew/mentat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.37" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-mentat-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-mentat-GHSA-hmq2-w58f-27jc.json index 24a02986cd1..f8661a5c344 100644 --- a/advisories/BREW-mentat-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-mentat-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mentat-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:13:16Z", - "modified": "2026-08-29T09:17:15Z", + "modified": "2026-09-04T09:30:36Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mentat-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-mentat-GHSA-jm78-9fvv-mhgr.json index 0d2a9e260b5..5d87886a30f 100644 --- a/advisories/BREW-mentat-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-mentat-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mentat-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:13:16Z", - "modified": "2026-08-29T09:17:15Z", + "modified": "2026-09-04T09:30:36Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.37", + "key": "pkg:pypi/gitpython@3.1.37", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mistral-vibe-CVE-2026-76221.json b/advisories/BREW-mistral-vibe-CVE-2026-76221.json index 470b9887b07..93157f96c03 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-76221.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-76221", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-23T21:08:24Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mistral-vibe-CVE-2026-76222.json b/advisories/BREW-mistral-vibe-CVE-2026-76222.json index d9633f340b9..49716da186a 100644 --- a/advisories/BREW-mistral-vibe-CVE-2026-76222.json +++ b/advisories/BREW-mistral-vibe-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-CVE-2026-76222", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-23T21:08:24Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mistral-vibe-CVE-2026-78675.json b/advisories/BREW-mistral-vibe-CVE-2026-78675.json new file mode 100644 index 00000000000..dea0463813b --- /dev/null +++ b/advisories/BREW-mistral-vibe-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mistral-vibe-CVE-2026-78675", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mistral-vibe", + "purl": "pkg:brew/mistral-vibe" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-mistral-vibe-CVE-2026-78676.json b/advisories/BREW-mistral-vibe-CVE-2026-78676.json new file mode 100644 index 00000000000..a049d8b013d --- /dev/null +++ b/advisories/BREW-mistral-vibe-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mistral-vibe-CVE-2026-78676", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mistral-vibe", + "purl": "pkg:brew/mistral-vibe" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-mistral-vibe-CVE-2026-78677.json b/advisories/BREW-mistral-vibe-CVE-2026-78677.json new file mode 100644 index 00000000000..c2a6753d32c --- /dev/null +++ b/advisories/BREW-mistral-vibe-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mistral-vibe-CVE-2026-78677", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mistral-vibe", + "purl": "pkg:brew/mistral-vibe" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-mistral-vibe-CVE-2026-78678.json b/advisories/BREW-mistral-vibe-CVE-2026-78678.json new file mode 100644 index 00000000000..c4472154690 --- /dev/null +++ b/advisories/BREW-mistral-vibe-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mistral-vibe-CVE-2026-78678", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mistral-vibe", + "purl": "pkg:brew/mistral-vibe" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-mistral-vibe-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-mistral-vibe-GHSA-hmq2-w58f-27jc.json index 4e317e1ac54..4e5f6847a09 100644 --- a/advisories/BREW-mistral-vibe-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-mistral-vibe-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-29T09:19:43Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr.json index fbce2f7970d..2d6f728e397 100644 --- a/advisories/BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mistral-vibe-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-29T09:19:43Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mk-CVE-2026-76221.json b/advisories/BREW-mk-CVE-2026-76221.json index 965a58b75f6..e6a0b9a15cc 100644 --- a/advisories/BREW-mk-CVE-2026-76221.json +++ b/advisories/BREW-mk-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mk-CVE-2026-76221", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-20T09:17:34Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mk-CVE-2026-76222.json b/advisories/BREW-mk-CVE-2026-76222.json index 0335418d5c6..d69074e49b5 100644 --- a/advisories/BREW-mk-CVE-2026-76222.json +++ b/advisories/BREW-mk-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mk-CVE-2026-76222", "published": "2026-08-20T09:17:34Z", - "modified": "2026-08-20T09:17:34Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mk-CVE-2026-78675.json b/advisories/BREW-mk-CVE-2026-78675.json new file mode 100644 index 00000000000..75e6a964c70 --- /dev/null +++ b/advisories/BREW-mk-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mk-CVE-2026-78675", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mk", + "purl": "pkg:brew/mk" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-mk-CVE-2026-78676.json b/advisories/BREW-mk-CVE-2026-78676.json new file mode 100644 index 00000000000..4f79328c2f9 --- /dev/null +++ b/advisories/BREW-mk-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mk-CVE-2026-78676", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mk", + "purl": "pkg:brew/mk" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-mk-CVE-2026-78677.json b/advisories/BREW-mk-CVE-2026-78677.json new file mode 100644 index 00000000000..50da977430b --- /dev/null +++ b/advisories/BREW-mk-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mk-CVE-2026-78677", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mk", + "purl": "pkg:brew/mk" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-mk-CVE-2026-78678.json b/advisories/BREW-mk-CVE-2026-78678.json new file mode 100644 index 00000000000..8b94408b7d8 --- /dev/null +++ b/advisories/BREW-mk-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mk-CVE-2026-78678", + "published": "2026-09-04T09:31:29Z", + "modified": "2026-09-04T09:31:29Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mk", + "purl": "pkg:brew/mk" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-mk-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-mk-GHSA-hmq2-w58f-27jc.json index 6a5c517bd74..3fd2623016e 100644 --- a/advisories/BREW-mk-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-mk-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mk-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-29T09:19:43Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mk-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-mk-GHSA-jm78-9fvv-mhgr.json index 11a7582103e..489971b92a1 100644 --- a/advisories/BREW-mk-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-mk-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-mk-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:14:16Z", - "modified": "2026-08-29T09:19:43Z", + "modified": "2026-09-04T09:31:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-mkdocs-material-CVE-2026-73295.json b/advisories/BREW-mkdocs-material-CVE-2026-73295.json new file mode 100644 index 00000000000..b55c7fefba0 --- /dev/null +++ b/advisories/BREW-mkdocs-material-CVE-2026-73295.json @@ -0,0 +1,100 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-mkdocs-material-CVE-2026-73295", + "published": "2026-09-04T09:32:39Z", + "modified": "2026-09-04T09:32:39Z", + "upstream": [ + "GHSA-xvg9-69gf-fjrf", + "CVE-2026-73295" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "mkdocs-material", + "purl": "pkg:brew/mkdocs-material" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.7.7" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "9.7.7" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "mkdocs-material", + "subject_version": "9.7.7", + "key": "pkg:pypi/mkdocs-material@9.7.7" + }, + { + "strategy": "distro", + "ecosystem": "Debian", + "name": "mkdocs-material", + "key": "Debian/mkdocs-material" + }, + { + "strategy": "distro", + "ecosystem": "PyPI", + "name": "mkdocs-material", + "subject_version": "9.7.7", + "key": "upstream:pkg:pypi/mkdocs-material@9.7.7" + }, + { + "strategy": "distro", + "ecosystem": "Ubuntu", + "name": "mkdocs-material", + "key": "Ubuntu/mkdocs-material" + } + ] + }, + "summary": "Material for MkDocs: DOM XSS in search suggestions via query parameter", + "details": "### Impact\n\nMaterial for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional `search.suggest` feature. A crafted `q` URL parameter could execute JavaScript in the documentation site's origin after user interaction.\n\n### Patches\n\nThe issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later.\n\n### Workarounds\n\nSites unable to upgrade should disable the `search.suggest` feature.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73295" + }, + { + "type": "WEB", + "url": "https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25" + }, + { + "type": "PACKAGE", + "url": "https://github.com/squidfunk/mkdocs-material" + }, + { + "type": "WEB", + "url": "https://github.com/squidfunk/mkdocs-material/releases/tag/9.7.7" + } + ] +} diff --git a/advisories/BREW-mycli-CVE-2021-32839.json b/advisories/BREW-mycli-CVE-2021-32839.json index fa4f97f613f..8451a14dce6 100644 --- a/advisories/BREW-mycli-CVE-2021-32839.json +++ b/advisories/BREW-mycli-CVE-2021-32839.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2021-32839", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-p5w8-wqhj-9hhf", "CVE-2021-32839", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.4.2", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2023-30608.json b/advisories/BREW-mycli-CVE-2023-30608.json index 50d6771ddc4..fc0d57dfaec 100644 --- a/advisories/BREW-mycli-CVE-2023-30608.json +++ b/advisories/BREW-mycli-CVE-2023-30608.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2023-30608", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-rrm6-wvj7-cwh2", "CVE-2023-30608", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.4.4", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2023-44690.json b/advisories/BREW-mycli-CVE-2023-44690.json index a8ed820ca6e..c299d5394f1 100644 --- a/advisories/BREW-mycli-CVE-2023-44690.json +++ b/advisories/BREW-mycli-CVE-2023-44690.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2023-44690", "published": "2026-08-13T17:16:44Z", - "modified": "2026-09-02T09:27:36Z", + "modified": "2026-09-04T09:35:11Z", "upstream": [ "GHSA-v9vj-9pxv-mr2w", "CVE-2023-44690", @@ -40,15 +40,15 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "mycli", - "subject_version": "2.18.5", - "key": "pkg:pypi/mycli@2.18.5" + "subject_version": "2.19.0", + "key": "pkg:pypi/mycli@2.19.0" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "mycli", - "subject_version": "2.18.5", - "key": "pkg:pypi/mycli@2.18.5" + "subject_version": "2.19.0", + "key": "pkg:pypi/mycli@2.19.0" }, { "strategy": "distro", @@ -60,8 +60,8 @@ "strategy": "distro", "ecosystem": "PyPI", "name": "mycli", - "subject_version": "2.18.5", - "key": "upstream:pkg:pypi/mycli@2.18.5" + "subject_version": "2.19.0", + "key": "upstream:pkg:pypi/mycli@2.19.0" }, { "strategy": "distro", diff --git a/advisories/BREW-mycli-CVE-2024-4340.json b/advisories/BREW-mycli-CVE-2024-4340.json index 5998f3fd036..d7d7d0caa9a 100644 --- a/advisories/BREW-mycli-CVE-2024-4340.json +++ b/advisories/BREW-mycli-CVE-2024-4340.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2024-4340", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-09-04T09:35:11Z", "upstream": [ "GHSA-2m57-hf25-phgg", "CVE-2024-4340", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.5.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2026-31236.json b/advisories/BREW-mycli-CVE-2026-31236.json index 0921afa72e4..e3572d1a4f4 100644 --- a/advisories/BREW-mycli-CVE-2026-31236.json +++ b/advisories/BREW-mycli-CVE-2026-31236.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-31236", "published": "2026-08-13T17:16:44Z", - "modified": "2026-09-03T09:36:22Z", + "modified": "2026-09-04T09:35:11Z", "upstream": [ "GHSA-g76p-4vg5-f4qh", "CVE-2026-31236", @@ -32,7 +32,7 @@ "fix": "bump", "range_state": "fixed", "resource": "llm", - "resource_purl": "pkg:pypi/llm@0.33" + "resource_purl": "pkg:pypi/llm@0.34" } } ], @@ -45,16 +45,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "llm", - "subject_version": "0.33", - "key": "pkg:pypi/llm@0.33", + "subject_version": "0.34", + "key": "pkg:pypi/llm@0.34", "resource": "llm" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "llm", - "subject_version": "0.33", - "key": "pkg:pypi/llm@0.33", + "subject_version": "0.34", + "key": "pkg:pypi/llm@0.34", "resource": "llm" } ] diff --git a/advisories/BREW-mycli-CVE-2026-54284.json b/advisories/BREW-mycli-CVE-2026-54284.json index ea12221e43a..d2c97da469c 100644 --- a/advisories/BREW-mycli-CVE-2026-54284.json +++ b/advisories/BREW-mycli-CVE-2026-54284.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-54284", "published": "2026-08-18T09:19:28Z", - "modified": "2026-08-20T09:21:59Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-pwgv-4x5q-6m9f", "CVE-2026-54284", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.19.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.6.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -43,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2026-59893.json b/advisories/BREW-mycli-CVE-2026-59893.json index c7363dd69ab..2929be0617e 100644 --- a/advisories/BREW-mycli-CVE-2026-59893.json +++ b/advisories/BREW-mycli-CVE-2026-59893.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-59893", "published": "2026-08-18T09:19:28Z", - "modified": "2026-08-20T09:21:59Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-prg7-hcfm-mfcr", "CVE-2026-59893", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.19.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.6.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -43,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2026-59894.json b/advisories/BREW-mycli-CVE-2026-59894.json index 572e5257e3e..dcf764658ed 100644 --- a/advisories/BREW-mycli-CVE-2026-59894.json +++ b/advisories/BREW-mycli-CVE-2026-59894.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-59894", "published": "2026-08-17T17:34:03Z", - "modified": "2026-08-20T09:21:59Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-3496-9g83-7v6x", "CVE-2026-59894", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.19.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.6.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -43,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2026-71491.json b/advisories/BREW-mycli-CVE-2026-71491.json index b7bec73cb4b..ff07c787895 100644 --- a/advisories/BREW-mycli-CVE-2026-71491.json +++ b/advisories/BREW-mycli-CVE-2026-71491.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-71491", "published": "2026-08-17T17:34:03Z", - "modified": "2026-08-20T09:21:59Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-f2ff-p2ww-7p4p", "CVE-2026-71491", @@ -21,16 +21,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.19.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.6.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -43,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-CVE-2026-7246.json b/advisories/BREW-mycli-CVE-2026-7246.json index 941813b0c03..d8badfb0431 100644 --- a/advisories/BREW-mycli-CVE-2026-7246.json +++ b/advisories/BREW-mycli-CVE-2026-7246.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-7246", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-09-04T09:35:11Z", "upstream": [ "PYSEC-2026-2132", "CVE-2026-7246", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "8.3.3", "resource": "click", - "resource_purl": "pkg:pypi/click@8.3.3" + "resource_purl": "pkg:pypi/click@8.5.0" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "click", - "subject_version": "8.3.3", - "key": "pkg:pypi/click@8.3.3", + "subject_version": "8.5.0", + "key": "pkg:pypi/click@8.5.0", "resource": "click" } ] diff --git a/advisories/BREW-mycli-CVE-2026-84305.json b/advisories/BREW-mycli-CVE-2026-84305.json index c3876c3b698..e8eeb5ce81b 100644 --- a/advisories/BREW-mycli-CVE-2026-84305.json +++ b/advisories/BREW-mycli-CVE-2026-84305.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-CVE-2026-84305", "published": "2026-09-02T09:27:36Z", - "modified": "2026-09-02T09:27:36Z", + "modified": "2026-09-04T09:36:23Z", "upstream": [ "GHSA-cfqr-cjx5-5jcm", "CVE-2026-84305" @@ -20,16 +20,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.19.0" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "0.6.0", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -42,8 +45,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-mycli-GHSA-27jp-wm6q-gp25.json b/advisories/BREW-mycli-GHSA-27jp-wm6q-gp25.json index fd5169e3f9e..c3996a7f9bb 100644 --- a/advisories/BREW-mycli-GHSA-27jp-wm6q-gp25.json +++ b/advisories/BREW-mycli-GHSA-27jp-wm6q-gp25.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-mycli-GHSA-27jp-wm6q-gp25", "published": "2026-08-13T17:16:44Z", - "modified": "2026-08-13T17:16:44Z", + "modified": "2026-09-04T09:35:11Z", "upstream": [ "GHSA-27jp-wm6q-gp25" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.5.4", "resource": "sqlparse", - "resource_purl": "pkg:pypi/sqlparse@0.5.5" + "resource_purl": "pkg:pypi/sqlparse@0.6.0" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "sqlparse", - "subject_version": "0.5.5", - "key": "pkg:pypi/sqlparse@0.5.5", + "subject_version": "0.6.0", + "key": "pkg:pypi/sqlparse@0.6.0", "resource": "sqlparse" } ] diff --git a/advisories/BREW-n8n-mcp-CVE-2026-39974.json b/advisories/BREW-n8n-mcp-CVE-2026-39974.json index 45ba4737a1e..50c159785e1 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-39974.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-39974.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-39974", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-4ggg-h7ph-26qr", "CVE-2026-39974" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-41495.json b/advisories/BREW-n8n-mcp-CVE-2026-41495.json index 96c3e521357..415a7fb46fe 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-41495.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-41495.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-41495", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-pfm2-2mhg-8wpx", "CVE-2026-41495" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-42282.json b/advisories/BREW-n8n-mcp-CVE-2026-42282.json index 38603b8767b..cbf147fcaf4 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-42282.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-42282.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-42282", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-wg4g-395p-mqv3", "CVE-2026-42282" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-42449.json b/advisories/BREW-n8n-mcp-CVE-2026-42449.json index 500e26213e1..2173340f239 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-42449.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-42449.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-42449", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-56c3-vfp2-5qqj", "CVE-2026-42449" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-44694.json b/advisories/BREW-n8n-mcp-CVE-2026-44694.json index 58155caf099..d3368098911 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-44694.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-44694.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-44694", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-cmrh-wvq6-wm9r", "CVE-2026-44694" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-45582.json b/advisories/BREW-n8n-mcp-CVE-2026-45582.json index 9e633fabcf1..c9abbecb752 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-45582.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-45582.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-45582", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-f3rg-xqjj-cj9w", "CVE-2026-45582" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-45707.json b/advisories/BREW-n8n-mcp-CVE-2026-45707.json index 218c9f1332e..826ff9fc7f8 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-45707.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-45707.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-45707", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-jxx9-px88-pj69", "CVE-2026-45707" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-54052.json b/advisories/BREW-n8n-mcp-CVE-2026-54052.json index feea10e110d..f6d1e4abf0b 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-54052.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-54052.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-54052", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-j6r7-6fhx-77wx", "CVE-2026-54052" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-CVE-2026-55608.json b/advisories/BREW-n8n-mcp-CVE-2026-55608.json index 04d352aeb08..0386ba82c6c 100644 --- a/advisories/BREW-n8n-mcp-CVE-2026-55608.json +++ b/advisories/BREW-n8n-mcp-CVE-2026-55608.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-CVE-2026-55608", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-2cf7-hpwf-47h9", "CVE-2026-55608" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json b/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json index bc9fbc0acc8..b067f7881d1 100644 --- a/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json +++ b/advisories/BREW-n8n-mcp-GHSA-75hx-xj24-mqrw.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-GHSA-75hx-xj24-mqrw", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-75hx-xj24-mqrw" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json b/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json index 96921dcaf92..6e60d7d5ca6 100644 --- a/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json +++ b/advisories/BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-n8n-mcp-GHSA-8g7g-hmwm-6rv2", "published": "2026-08-13T17:16:54Z", - "modified": "2026-09-02T09:27:45Z", + "modified": "2026-09-04T09:36:33Z", "upstream": [ "GHSA-8g7g-hmwm-6rv2" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "n8n-mcp", - "subject_version": "2.77.0", - "key": "pkg:npm/n8n-mcp@2.77.0" + "subject_version": "2.79.0", + "key": "pkg:npm/n8n-mcp@2.79.0" } ] }, diff --git a/advisories/BREW-nbdime-CVE-2026-76221.json b/advisories/BREW-nbdime-CVE-2026-76221.json index d4b0e252945..7f2a0ea8fa1 100644 --- a/advisories/BREW-nbdime-CVE-2026-76221.json +++ b/advisories/BREW-nbdime-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-nbdime-CVE-2026-76221", "published": "2026-08-20T09:22:15Z", - "modified": "2026-08-20T09:22:15Z", + "modified": "2026-09-04T09:36:43Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-nbdime-CVE-2026-76222.json b/advisories/BREW-nbdime-CVE-2026-76222.json index ff0683d8135..f1ff8fc54fd 100644 --- a/advisories/BREW-nbdime-CVE-2026-76222.json +++ b/advisories/BREW-nbdime-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-nbdime-CVE-2026-76222", "published": "2026-08-20T09:22:15Z", - "modified": "2026-08-20T09:22:15Z", + "modified": "2026-09-04T09:36:43Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-nbdime-CVE-2026-78675.json b/advisories/BREW-nbdime-CVE-2026-78675.json new file mode 100644 index 00000000000..5fda5a6d81c --- /dev/null +++ b/advisories/BREW-nbdime-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-nbdime-CVE-2026-78675", + "published": "2026-09-04T09:36:43Z", + "modified": "2026-09-04T09:36:43Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "nbdime", + "purl": "pkg:brew/nbdime" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-nbdime-CVE-2026-78676.json b/advisories/BREW-nbdime-CVE-2026-78676.json new file mode 100644 index 00000000000..2bcc58139cb --- /dev/null +++ b/advisories/BREW-nbdime-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-nbdime-CVE-2026-78676", + "published": "2026-09-04T09:36:43Z", + "modified": "2026-09-04T09:36:43Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "nbdime", + "purl": "pkg:brew/nbdime" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-nbdime-CVE-2026-78677.json b/advisories/BREW-nbdime-CVE-2026-78677.json new file mode 100644 index 00000000000..643fa4b3d90 --- /dev/null +++ b/advisories/BREW-nbdime-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-nbdime-CVE-2026-78677", + "published": "2026-09-04T09:36:43Z", + "modified": "2026-09-04T09:36:43Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "nbdime", + "purl": "pkg:brew/nbdime" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-nbdime-CVE-2026-78678.json b/advisories/BREW-nbdime-CVE-2026-78678.json new file mode 100644 index 00000000000..6664fd0e7b1 --- /dev/null +++ b/advisories/BREW-nbdime-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-nbdime-CVE-2026-78678", + "published": "2026-09-04T09:36:43Z", + "modified": "2026-09-04T09:36:43Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "nbdime", + "purl": "pkg:brew/nbdime" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-nbdime-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-nbdime-GHSA-hmq2-w58f-27jc.json index 195f8dbbfad..77bf4a1aedd 100644 --- a/advisories/BREW-nbdime-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-nbdime-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-nbdime-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:17:04Z", - "modified": "2026-08-29T09:22:33Z", + "modified": "2026-09-04T09:36:43Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-nbdime-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-nbdime-GHSA-jm78-9fvv-mhgr.json index 76c0d05306d..b68ec878082 100644 --- a/advisories/BREW-nbdime-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-nbdime-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-nbdime-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:17:04Z", - "modified": "2026-08-29T09:22:33Z", + "modified": "2026-09-04T09:36:43Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-nx-CVE-2026-54753.json b/advisories/BREW-nx-CVE-2026-54753.json index 8c0c0d46db9..e718ce6c92c 100644 --- a/advisories/BREW-nx-CVE-2026-54753.json +++ b/advisories/BREW-nx-CVE-2026-54753.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-nx-CVE-2026-54753", "published": "2026-08-13T17:19:21Z", - "modified": "2026-09-02T09:30:17Z", + "modified": "2026-09-04T09:39:03Z", "upstream": [ "GHSA-g2r8-wvmj-jf5w", "CVE-2026-54753" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "nx", - "subject_version": "23.1.3", - "key": "pkg:npm/nx@23.1.3" + "subject_version": "23.2.0", + "key": "pkg:npm/nx@23.2.0" } ] }, diff --git a/advisories/BREW-nx-CVE-2026-71476.json b/advisories/BREW-nx-CVE-2026-71476.json index 98202dcd380..f1b461894d9 100644 --- a/advisories/BREW-nx-CVE-2026-71476.json +++ b/advisories/BREW-nx-CVE-2026-71476.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-nx-CVE-2026-71476", "published": "2026-08-13T17:19:21Z", - "modified": "2026-09-02T09:30:17Z", + "modified": "2026-09-04T09:39:03Z", "upstream": [ "GHSA-vp3h-ghgh-jr7g", "CVE-2026-71476" @@ -43,8 +43,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "nx", - "subject_version": "23.1.3", - "key": "pkg:npm/nx@23.1.3" + "subject_version": "23.2.0", + "key": "pkg:npm/nx@23.2.0" } ] }, diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-76221.json b/advisories/BREW-opentimestamps-client-CVE-2026-76221.json index 2d29f225ebd..08f725a7198 100644 --- a/advisories/BREW-opentimestamps-client-CVE-2026-76221.json +++ b/advisories/BREW-opentimestamps-client-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-opentimestamps-client-CVE-2026-76221", "published": "2026-08-20T09:30:00Z", - "modified": "2026-08-20T09:30:00Z", + "modified": "2026-09-04T09:43:41Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-76222.json b/advisories/BREW-opentimestamps-client-CVE-2026-76222.json index 6a73eb30e09..597eb97d846 100644 --- a/advisories/BREW-opentimestamps-client-CVE-2026-76222.json +++ b/advisories/BREW-opentimestamps-client-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-opentimestamps-client-CVE-2026-76222", "published": "2026-08-20T09:30:00Z", - "modified": "2026-08-20T09:30:00Z", + "modified": "2026-09-04T09:43:41Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-78675.json b/advisories/BREW-opentimestamps-client-CVE-2026-78675.json new file mode 100644 index 00000000000..d09b594bbd4 --- /dev/null +++ b/advisories/BREW-opentimestamps-client-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-opentimestamps-client-CVE-2026-78675", + "published": "2026-09-04T09:43:41Z", + "modified": "2026-09-04T09:43:41Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "opentimestamps-client", + "purl": "pkg:brew/opentimestamps-client" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-78676.json b/advisories/BREW-opentimestamps-client-CVE-2026-78676.json new file mode 100644 index 00000000000..9d9e777d696 --- /dev/null +++ b/advisories/BREW-opentimestamps-client-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-opentimestamps-client-CVE-2026-78676", + "published": "2026-09-04T09:43:41Z", + "modified": "2026-09-04T09:43:41Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "opentimestamps-client", + "purl": "pkg:brew/opentimestamps-client" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-78677.json b/advisories/BREW-opentimestamps-client-CVE-2026-78677.json new file mode 100644 index 00000000000..b6a227abe10 --- /dev/null +++ b/advisories/BREW-opentimestamps-client-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-opentimestamps-client-CVE-2026-78677", + "published": "2026-09-04T09:43:41Z", + "modified": "2026-09-04T09:43:41Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "opentimestamps-client", + "purl": "pkg:brew/opentimestamps-client" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-opentimestamps-client-CVE-2026-78678.json b/advisories/BREW-opentimestamps-client-CVE-2026-78678.json new file mode 100644 index 00000000000..74cb9d0f9dc --- /dev/null +++ b/advisories/BREW-opentimestamps-client-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-opentimestamps-client-CVE-2026-78678", + "published": "2026-09-04T09:43:41Z", + "modified": "2026-09-04T09:43:41Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "opentimestamps-client", + "purl": "pkg:brew/opentimestamps-client" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-opentimestamps-client-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-opentimestamps-client-GHSA-hmq2-w58f-27jc.json index d567660ed05..2938f418cd5 100644 --- a/advisories/BREW-opentimestamps-client-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-opentimestamps-client-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-opentimestamps-client-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:24:07Z", - "modified": "2026-08-29T09:29:27Z", + "modified": "2026-09-04T09:43:41Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-opentimestamps-client-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-opentimestamps-client-GHSA-jm78-9fvv-mhgr.json index 5fe8ed5192c..ebe9a62e774 100644 --- a/advisories/BREW-opentimestamps-client-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-opentimestamps-client-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-opentimestamps-client-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:24:07Z", - "modified": "2026-08-29T09:29:27Z", + "modified": "2026-09-04T09:43:41Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-otterdog-CVE-2026-76221.json b/advisories/BREW-otterdog-CVE-2026-76221.json index bc4647b64e2..ad1672b8b83 100644 --- a/advisories/BREW-otterdog-CVE-2026-76221.json +++ b/advisories/BREW-otterdog-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-otterdog-CVE-2026-76221", "published": "2026-08-20T09:30:09Z", - "modified": "2026-08-20T09:30:09Z", + "modified": "2026-09-04T09:44:25Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-otterdog-CVE-2026-76222.json b/advisories/BREW-otterdog-CVE-2026-76222.json index dec92aa9b65..160073a910d 100644 --- a/advisories/BREW-otterdog-CVE-2026-76222.json +++ b/advisories/BREW-otterdog-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-otterdog-CVE-2026-76222", "published": "2026-08-20T09:30:09Z", - "modified": "2026-08-20T09:30:09Z", + "modified": "2026-09-04T09:44:25Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-otterdog-CVE-2026-78675.json b/advisories/BREW-otterdog-CVE-2026-78675.json new file mode 100644 index 00000000000..552ced3e75c --- /dev/null +++ b/advisories/BREW-otterdog-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-otterdog-CVE-2026-78675", + "published": "2026-09-04T09:44:25Z", + "modified": "2026-09-04T09:44:25Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "otterdog", + "purl": "pkg:brew/otterdog" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-otterdog-CVE-2026-78676.json b/advisories/BREW-otterdog-CVE-2026-78676.json new file mode 100644 index 00000000000..41dff1dcdab --- /dev/null +++ b/advisories/BREW-otterdog-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-otterdog-CVE-2026-78676", + "published": "2026-09-04T09:44:25Z", + "modified": "2026-09-04T09:44:25Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "otterdog", + "purl": "pkg:brew/otterdog" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-otterdog-CVE-2026-78677.json b/advisories/BREW-otterdog-CVE-2026-78677.json new file mode 100644 index 00000000000..f5cdf86eb93 --- /dev/null +++ b/advisories/BREW-otterdog-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-otterdog-CVE-2026-78677", + "published": "2026-09-04T09:44:25Z", + "modified": "2026-09-04T09:44:25Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "otterdog", + "purl": "pkg:brew/otterdog" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-otterdog-CVE-2026-78678.json b/advisories/BREW-otterdog-CVE-2026-78678.json new file mode 100644 index 00000000000..b620c7d1263 --- /dev/null +++ b/advisories/BREW-otterdog-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-otterdog-CVE-2026-78678", + "published": "2026-09-04T09:44:25Z", + "modified": "2026-09-04T09:44:25Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "otterdog", + "purl": "pkg:brew/otterdog" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-otterdog-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-otterdog-GHSA-hmq2-w58f-27jc.json index fee89e04091..4fc1afcea5c 100644 --- a/advisories/BREW-otterdog-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-otterdog-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-otterdog-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-29T09:30:12Z", + "modified": "2026-09-04T09:44:25Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-otterdog-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-otterdog-GHSA-jm78-9fvv-mhgr.json index c3e8e8bfb0e..f42006b8ad3 100644 --- a/advisories/BREW-otterdog-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-otterdog-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-otterdog-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:24:19Z", - "modified": "2026-08-29T09:30:12Z", + "modified": "2026-09-04T09:44:25Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-prowler-CVE-2015-5237.json b/advisories/BREW-prowler-CVE-2015-5237.json index 2a2e257a4f3..7ebd1305994 100644 --- a/advisories/BREW-prowler-CVE-2015-5237.json +++ b/advisories/BREW-prowler-CVE-2015-5237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2015-5237", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-jwvw-v7c5-m82h", "CVE-2015-5237", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.4.0", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@7.36.0" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-prowler-CVE-2016-6298.json b/advisories/BREW-prowler-CVE-2016-6298.json index 27f7e3f7983..39336021860 100644 --- a/advisories/BREW-prowler-CVE-2016-6298.json +++ b/advisories/BREW-prowler-CVE-2016-6298.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2016-6298", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-wg33-x934-3ghh", "CVE-2016-6298", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "0.3.2", "resource": "jwcrypto", - "resource_purl": "pkg:pypi/jwcrypto@1.5.9" + "resource_purl": "pkg:pypi/jwcrypto@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" } ] diff --git a/advisories/BREW-prowler-CVE-2021-22570.json b/advisories/BREW-prowler-CVE-2021-22570.json index a231cbc548f..8ea92814373 100644 --- a/advisories/BREW-prowler-CVE-2021-22570.json +++ b/advisories/BREW-prowler-CVE-2021-22570.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2021-22570", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "PYSEC-2022-48", "CVE-2021-22570", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.15.0", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@7.36.0" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,8 +46,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-prowler-CVE-2022-1941.json b/advisories/BREW-prowler-CVE-2022-1941.json index 4d0b4eb4c5e..bd0aed5459d 100644 --- a/advisories/BREW-prowler-CVE-2022-1941.json +++ b/advisories/BREW-prowler-CVE-2022-1941.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2022-1941", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-8gq9-2x98-w8hf", "CVE-2022-1941", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "4.21.6", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@7.36.0" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-prowler-CVE-2022-3102.json b/advisories/BREW-prowler-CVE-2022-3102.json index 9b1ad4615f4..2a621bd4641 100644 --- a/advisories/BREW-prowler-CVE-2022-3102.json +++ b/advisories/BREW-prowler-CVE-2022-3102.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2022-3102", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-gwp4-mcv4-w95j", "CVE-2022-3102", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.4", "resource": "jwcrypto", - "resource_purl": "pkg:pypi/jwcrypto@1.5.9" + "resource_purl": "pkg:pypi/jwcrypto@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" } ] diff --git a/advisories/BREW-prowler-CVE-2023-26145.json b/advisories/BREW-prowler-CVE-2023-26145.json index 0aba3272c19..ffe45e7f795 100644 --- a/advisories/BREW-prowler-CVE-2023-26145.json +++ b/advisories/BREW-prowler-CVE-2023-26145.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2023-26145", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-13T17:29:23Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-8mjr-6c96-39w8", "CVE-2023-26145", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.0.0", "resource": "pydash", - "resource_purl": "pkg:pypi/pydash@8.0.6" + "resource_purl": "pkg:pypi/pydash@8.1.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "pydash", - "subject_version": "8.0.6", - "key": "pkg:pypi/pydash@8.0.6", + "subject_version": "8.1.0", + "key": "pkg:pypi/pydash@8.1.0", "resource": "pydash" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "pydash", - "subject_version": "8.0.6", - "key": "pkg:pypi/pydash@8.0.6", + "subject_version": "8.1.0", + "key": "pkg:pypi/pydash@8.1.0", "resource": "pydash" } ] diff --git a/advisories/BREW-prowler-CVE-2023-6681.json b/advisories/BREW-prowler-CVE-2023-6681.json index d614529891a..769a039cdc6 100644 --- a/advisories/BREW-prowler-CVE-2023-6681.json +++ b/advisories/BREW-prowler-CVE-2023-6681.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2023-6681", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-cw2r-4p82-qv79", "CVE-2023-6681", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.1", "resource": "jwcrypto", - "resource_purl": "pkg:pypi/jwcrypto@1.5.9" + "resource_purl": "pkg:pypi/jwcrypto@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" } ] diff --git a/advisories/BREW-prowler-CVE-2024-28102.json b/advisories/BREW-prowler-CVE-2024-28102.json index 4d81358d891..9ae1d39f9e2 100644 --- a/advisories/BREW-prowler-CVE-2024-28102.json +++ b/advisories/BREW-prowler-CVE-2024-28102.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2024-28102", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-j857-7rvv-vj97", "CVE-2024-28102", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.6", "resource": "jwcrypto", - "resource_purl": "pkg:pypi/jwcrypto@1.5.9" + "resource_purl": "pkg:pypi/jwcrypto@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" } ] diff --git a/advisories/BREW-prowler-CVE-2025-4565.json b/advisories/BREW-prowler-CVE-2025-4565.json index 3dde1682da8..f7a40694c1c 100644 --- a/advisories/BREW-prowler-CVE-2025-4565.json +++ b/advisories/BREW-prowler-CVE-2025-4565.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2025-4565", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-8qvm-5x2c-j2w7", "CVE-2025-4565", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.31.1", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@7.36.0" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-prowler-CVE-2025-68146.json b/advisories/BREW-prowler-CVE-2025-68146.json index bde6619b1fe..c0b13ecdce3 100644 --- a/advisories/BREW-prowler-CVE-2025-68146.json +++ b/advisories/BREW-prowler-CVE-2025-68146.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2025-68146", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-w853-jp5j-5j7f", "CVE-2025-68146", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.1", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.4" + "resource_purl": "pkg:pypi/filelock@3.32.5" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" } ] diff --git a/advisories/BREW-prowler-CVE-2026-0994.json b/advisories/BREW-prowler-CVE-2026-0994.json index 90b526f6cf3..f7f5989eda7 100644 --- a/advisories/BREW-prowler-CVE-2026-0994.json +++ b/advisories/BREW-prowler-CVE-2026-0994.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2026-0994", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-7gcm-g887-7qv7", "CVE-2026-0994", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.33.5", "resource": "protobuf", - "resource_purl": "pkg:pypi/protobuf@7.36.0" + "resource_purl": "pkg:pypi/protobuf@7.36.1" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "protobuf", - "subject_version": "7.36.0", - "key": "pkg:pypi/protobuf@7.36.0", + "subject_version": "7.36.1", + "key": "pkg:pypi/protobuf@7.36.1", "resource": "protobuf" } ] diff --git a/advisories/BREW-prowler-CVE-2026-22701.json b/advisories/BREW-prowler-CVE-2026-22701.json index ac92db4ab16..ae06e32593d 100644 --- a/advisories/BREW-prowler-CVE-2026-22701.json +++ b/advisories/BREW-prowler-CVE-2026-22701.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2026-22701", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-qmgc-5h2g-mvrw", "CVE-2026-22701", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.20.3", "resource": "filelock", - "resource_purl": "pkg:pypi/filelock@3.32.4" + "resource_purl": "pkg:pypi/filelock@3.32.5" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "filelock", - "subject_version": "3.32.4", - "key": "pkg:pypi/filelock@3.32.4", + "subject_version": "3.32.5", + "key": "pkg:pypi/filelock@3.32.5", "resource": "filelock" } ] diff --git a/advisories/BREW-prowler-CVE-2026-39373.json b/advisories/BREW-prowler-CVE-2026-39373.json index 0a5d057da1f..5e41763b961 100644 --- a/advisories/BREW-prowler-CVE-2026-39373.json +++ b/advisories/BREW-prowler-CVE-2026-39373.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-prowler-CVE-2026-39373", "published": "2026-08-13T17:29:23Z", - "modified": "2026-08-30T09:42:27Z", + "modified": "2026-09-04T09:48:46Z", "upstream": [ "GHSA-fjrm-76x2-c4q4", "CVE-2026-39373", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "1.5.7", "resource": "jwcrypto", - "resource_purl": "pkg:pypi/jwcrypto@1.5.9" + "resource_purl": "pkg:pypi/jwcrypto@1.6.0" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "jwcrypto", - "subject_version": "1.5.9", - "key": "pkg:pypi/jwcrypto@1.5.9", + "subject_version": "1.6.0", + "key": "pkg:pypi/jwcrypto@1.6.0", "resource": "jwcrypto" } ] diff --git a/advisories/BREW-pygitup-CVE-2026-76221.json b/advisories/BREW-pygitup-CVE-2026-76221.json index 5cb43ffbe84..3964ba1af5b 100644 --- a/advisories/BREW-pygitup-CVE-2026-76221.json +++ b/advisories/BREW-pygitup-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-pygitup-CVE-2026-76221", "published": "2026-08-20T09:34:40Z", - "modified": "2026-08-20T09:34:40Z", + "modified": "2026-09-04T09:48:58Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pygitup-CVE-2026-76222.json b/advisories/BREW-pygitup-CVE-2026-76222.json index 35091eb1efc..9cf7e4f8972 100644 --- a/advisories/BREW-pygitup-CVE-2026-76222.json +++ b/advisories/BREW-pygitup-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-pygitup-CVE-2026-76222", "published": "2026-08-20T09:34:40Z", - "modified": "2026-08-20T09:34:40Z", + "modified": "2026-09-04T09:48:58Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pygitup-CVE-2026-78675.json b/advisories/BREW-pygitup-CVE-2026-78675.json new file mode 100644 index 00000000000..447139418e6 --- /dev/null +++ b/advisories/BREW-pygitup-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pygitup-CVE-2026-78675", + "published": "2026-09-04T09:50:12Z", + "modified": "2026-09-04T09:50:12Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pygitup", + "purl": "pkg:brew/pygitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.5.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-pygitup-CVE-2026-78676.json b/advisories/BREW-pygitup-CVE-2026-78676.json new file mode 100644 index 00000000000..4993923411a --- /dev/null +++ b/advisories/BREW-pygitup-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pygitup-CVE-2026-78676", + "published": "2026-09-04T09:50:12Z", + "modified": "2026-09-04T09:50:12Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pygitup", + "purl": "pkg:brew/pygitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.5.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-pygitup-CVE-2026-78677.json b/advisories/BREW-pygitup-CVE-2026-78677.json new file mode 100644 index 00000000000..c6e6a8eb177 --- /dev/null +++ b/advisories/BREW-pygitup-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pygitup-CVE-2026-78677", + "published": "2026-09-04T09:50:12Z", + "modified": "2026-09-04T09:50:12Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pygitup", + "purl": "pkg:brew/pygitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.5.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-pygitup-CVE-2026-78678.json b/advisories/BREW-pygitup-CVE-2026-78678.json new file mode 100644 index 00000000000..7a128af7910 --- /dev/null +++ b/advisories/BREW-pygitup-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pygitup-CVE-2026-78678", + "published": "2026-09-04T09:50:12Z", + "modified": "2026-09-04T09:50:12Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pygitup", + "purl": "pkg:brew/pygitup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.5.0" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.59" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-pygitup-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-pygitup-GHSA-hmq2-w58f-27jc.json index 6766129c931..4f2923f804d 100644 --- a/advisories/BREW-pygitup-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-pygitup-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-pygitup-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:29:36Z", - "modified": "2026-08-29T09:34:20Z", + "modified": "2026-09-04T09:48:58Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-pygitup-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-pygitup-GHSA-jm78-9fvv-mhgr.json index 0b5d7c986c3..ad2a80a77f3 100644 --- a/advisories/BREW-pygitup-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-pygitup-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-pygitup-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:29:36Z", - "modified": "2026-08-29T09:34:20Z", + "modified": "2026-09-04T09:48:58Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.59", + "key": "pkg:pypi/gitpython@3.1.59", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-renovate-CVE-2024-58376.json b/advisories/BREW-renovate-CVE-2024-58376.json index 50084828775..e9fb39e7c81 100644 --- a/advisories/BREW-renovate-CVE-2024-58376.json +++ b/advisories/BREW-renovate-CVE-2024-58376.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2024-58376", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2024-58376", "GHSA-rqgv-292v-5qgr" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76226.json b/advisories/BREW-renovate-CVE-2026-76226.json index c66a081b3c2..80d6603f628 100644 --- a/advisories/BREW-renovate-CVE-2026-76226.json +++ b/advisories/BREW-renovate-CVE-2026-76226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76226", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76226", "GHSA-5vjq-5jmg-39xq" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76227.json b/advisories/BREW-renovate-CVE-2026-76227.json index 750ee95fafb..357ad82eba6 100644 --- a/advisories/BREW-renovate-CVE-2026-76227.json +++ b/advisories/BREW-renovate-CVE-2026-76227.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76227", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76227", "GHSA-8wc6-vgrq-x6cf" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76228.json b/advisories/BREW-renovate-CVE-2026-76228.json index 36ab764ca06..fb904651770 100644 --- a/advisories/BREW-renovate-CVE-2026-76228.json +++ b/advisories/BREW-renovate-CVE-2026-76228.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76228", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76228", "GHSA-pfq2-hh62-7m96" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76229.json b/advisories/BREW-renovate-CVE-2026-76229.json index 06ec7ffb73f..0b54d4c1f3c 100644 --- a/advisories/BREW-renovate-CVE-2026-76229.json +++ b/advisories/BREW-renovate-CVE-2026-76229.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76229", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76229", "GHSA-xv56-3wq5-9997" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76230.json b/advisories/BREW-renovate-CVE-2026-76230.json index 2c03b09e768..90d83959e24 100644 --- a/advisories/BREW-renovate-CVE-2026-76230.json +++ b/advisories/BREW-renovate-CVE-2026-76230.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76230", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76230", "GHSA-fr4j-65pv-gjjj" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76231.json b/advisories/BREW-renovate-CVE-2026-76231.json index 608d46d983b..fd3cd3010e4 100644 --- a/advisories/BREW-renovate-CVE-2026-76231.json +++ b/advisories/BREW-renovate-CVE-2026-76231.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76231", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76231", "GHSA-36j9-mx87-2cff" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76232.json b/advisories/BREW-renovate-CVE-2026-76232.json index 7be83f271cc..37215d70efe 100644 --- a/advisories/BREW-renovate-CVE-2026-76232.json +++ b/advisories/BREW-renovate-CVE-2026-76232.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76232", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76232", "GHSA-3f44-xw83-3pmg" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-CVE-2026-76233.json b/advisories/BREW-renovate-CVE-2026-76233.json index b84ae5db1c3..dbc6f355141 100644 --- a/advisories/BREW-renovate-CVE-2026-76233.json +++ b/advisories/BREW-renovate-CVE-2026-76233.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-CVE-2026-76233", "published": "2026-08-20T09:37:20Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "CVE-2026-76233", "GHSA-xjr7-3c3g-m763" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-36j9-mx87-2cff.json b/advisories/BREW-renovate-GHSA-36j9-mx87-2cff.json index 51e21955687..e847e864f8a 100644 --- a/advisories/BREW-renovate-GHSA-36j9-mx87-2cff.json +++ b/advisories/BREW-renovate-GHSA-36j9-mx87-2cff.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-36j9-mx87-2cff", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-36j9-mx87-2cff", "CVE-2026-76231" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json b/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json index 972e7ef019f..7c70ef11df5 100644 --- a/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json +++ b/advisories/BREW-renovate-GHSA-36rh-ggpr-j3gj.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-36rh-ggpr-j3gj", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-36rh-ggpr-j3gj" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-3f44-xw83-3pmg.json b/advisories/BREW-renovate-GHSA-3f44-xw83-3pmg.json index dd7cc3ef2e4..292dd585307 100644 --- a/advisories/BREW-renovate-GHSA-3f44-xw83-3pmg.json +++ b/advisories/BREW-renovate-GHSA-3f44-xw83-3pmg.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-3f44-xw83-3pmg", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-3f44-xw83-3pmg", "CVE-2026-76232" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-5vjq-5jmg-39xq.json b/advisories/BREW-renovate-GHSA-5vjq-5jmg-39xq.json index c989a1bb437..3f3fdf12606 100644 --- a/advisories/BREW-renovate-GHSA-5vjq-5jmg-39xq.json +++ b/advisories/BREW-renovate-GHSA-5vjq-5jmg-39xq.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-5vjq-5jmg-39xq", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-5vjq-5jmg-39xq", "CVE-2026-76226" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-8wc6-vgrq-x6cf.json b/advisories/BREW-renovate-GHSA-8wc6-vgrq-x6cf.json index fb3934c4b2d..fc873f22e2e 100644 --- a/advisories/BREW-renovate-GHSA-8wc6-vgrq-x6cf.json +++ b/advisories/BREW-renovate-GHSA-8wc6-vgrq-x6cf.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-8wc6-vgrq-x6cf", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-8wc6-vgrq-x6cf", "CVE-2026-76227" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-fr4j-65pv-gjjj.json b/advisories/BREW-renovate-GHSA-fr4j-65pv-gjjj.json index 7ecde79c6ff..03561509118 100644 --- a/advisories/BREW-renovate-GHSA-fr4j-65pv-gjjj.json +++ b/advisories/BREW-renovate-GHSA-fr4j-65pv-gjjj.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-fr4j-65pv-gjjj", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-fr4j-65pv-gjjj", "CVE-2026-76230" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-pfq2-hh62-7m96.json b/advisories/BREW-renovate-GHSA-pfq2-hh62-7m96.json index d66462955bf..829f313d431 100644 --- a/advisories/BREW-renovate-GHSA-pfq2-hh62-7m96.json +++ b/advisories/BREW-renovate-GHSA-pfq2-hh62-7m96.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-pfq2-hh62-7m96", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-pfq2-hh62-7m96", "CVE-2026-76228" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-rqgv-292v-5qgr.json b/advisories/BREW-renovate-GHSA-rqgv-292v-5qgr.json index 7e15d58db18..3ff82532a19 100644 --- a/advisories/BREW-renovate-GHSA-rqgv-292v-5qgr.json +++ b/advisories/BREW-renovate-GHSA-rqgv-292v-5qgr.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-rqgv-292v-5qgr", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-rqgv-292v-5qgr", "CVE-2024-58376" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json b/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json index 1c12854210a..77c87c56ad4 100644 --- a/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json +++ b/advisories/BREW-renovate-GHSA-v7x3-7hw7-pcjg.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-v7x3-7hw7-pcjg", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-v7x3-7hw7-pcjg" ], @@ -42,8 +42,8 @@ "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-xjr7-3c3g-m763.json b/advisories/BREW-renovate-GHSA-xjr7-3c3g-m763.json index 58d72049297..9211efcda7d 100644 --- a/advisories/BREW-renovate-GHSA-xjr7-3c3g-m763.json +++ b/advisories/BREW-renovate-GHSA-xjr7-3c3g-m763.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-xjr7-3c3g-m763", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-xjr7-3c3g-m763", "CVE-2026-76233" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-renovate-GHSA-xv56-3wq5-9997.json b/advisories/BREW-renovate-GHSA-xv56-3wq5-9997.json index 468fed979ee..7d0e63e9729 100644 --- a/advisories/BREW-renovate-GHSA-xv56-3wq5-9997.json +++ b/advisories/BREW-renovate-GHSA-xv56-3wq5-9997.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-renovate-GHSA-xv56-3wq5-9997", "published": "2026-08-13T17:32:30Z", - "modified": "2026-09-03T10:00:41Z", + "modified": "2026-09-04T09:55:08Z", "upstream": [ "GHSA-xv56-3wq5-9997", "CVE-2026-76229" @@ -43,15 +43,15 @@ "strategy": "git", "ecosystem": "GIT", "name": "https://github.com/renovatebot/renovate", - "subject_version": "44.59.0", + "subject_version": "44.61.0", "key": "https://github.com/renovatebot/renovate" }, { "strategy": "registry", "ecosystem": "npm", "name": "renovate", - "subject_version": "44.59.0", - "key": "pkg:npm/renovate@44.59.0" + "subject_version": "44.61.0", + "key": "pkg:npm/renovate@44.61.0" } ] }, diff --git a/advisories/BREW-safety-CVE-2026-62384.json b/advisories/BREW-safety-CVE-2026-62384.json new file mode 100644 index 00000000000..ac8d6a3c750 --- /dev/null +++ b/advisories/BREW-safety-CVE-2026-62384.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-safety-CVE-2026-62384", + "published": "2026-09-04T09:59:23Z", + "modified": "2026-09-04T09:59:23Z", + "upstream": [ + "PYSEC-2026-3789", + "CVE-2026-62384", + "GHSA-f833-7jw8-xwrv" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "safety", + "purl": "pkg:brew/safety" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.8.1_2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.10.2", + "resource": "nltk", + "resource_purl": "pkg:pypi/nltk@3.10.3" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + } + ] + }, + "details": "NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/nltk-framenetcorpusreader-symlink-sandbox-bypass-before" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv" + } + ] +} diff --git a/advisories/BREW-safety-CVE-2026-71514.json b/advisories/BREW-safety-CVE-2026-71514.json index 195256b2e78..00eda4a7280 100644 --- a/advisories/BREW-safety-CVE-2026-71514.json +++ b/advisories/BREW-safety-CVE-2026-71514.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-safety-CVE-2026-71514", "published": "2026-09-03T10:05:22Z", - "modified": "2026-09-03T10:05:22Z", + "modified": "2026-09-04T09:57:44Z", "upstream": [ "GHSA-cv22-g7mw-8v73", - "CVE-2026-71514" + "CVE-2026-71514", + "PYSEC-2026-3790" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "nltk", + "subject_version": "3.10.3", + "key": "pkg:pypi/nltk@3.10.3", + "resource": "nltk" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-shallow-backup-CVE-2026-76221.json b/advisories/BREW-shallow-backup-CVE-2026-76221.json index 6cfc1052b8e..3b8d40c0058 100644 --- a/advisories/BREW-shallow-backup-CVE-2026-76221.json +++ b/advisories/BREW-shallow-backup-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-shallow-backup-CVE-2026-76221", "published": "2026-08-20T09:38:52Z", - "modified": "2026-08-20T09:38:52Z", + "modified": "2026-09-04T10:00:38Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-shallow-backup-CVE-2026-76222.json b/advisories/BREW-shallow-backup-CVE-2026-76222.json index 5587ff89776..5c3192a6835 100644 --- a/advisories/BREW-shallow-backup-CVE-2026-76222.json +++ b/advisories/BREW-shallow-backup-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-shallow-backup-CVE-2026-76222", "published": "2026-08-20T09:38:52Z", - "modified": "2026-08-20T09:38:52Z", + "modified": "2026-09-04T10:00:38Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-shallow-backup-CVE-2026-78675.json b/advisories/BREW-shallow-backup-CVE-2026-78675.json new file mode 100644 index 00000000000..7ba7622e0ec --- /dev/null +++ b/advisories/BREW-shallow-backup-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-shallow-backup-CVE-2026-78675", + "published": "2026-09-04T10:00:38Z", + "modified": "2026-09-04T10:00:38Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "shallow-backup", + "purl": "pkg:brew/shallow-backup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-shallow-backup-CVE-2026-78676.json b/advisories/BREW-shallow-backup-CVE-2026-78676.json new file mode 100644 index 00000000000..f4fac876060 --- /dev/null +++ b/advisories/BREW-shallow-backup-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-shallow-backup-CVE-2026-78676", + "published": "2026-09-04T10:00:38Z", + "modified": "2026-09-04T10:00:38Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "shallow-backup", + "purl": "pkg:brew/shallow-backup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-shallow-backup-CVE-2026-78677.json b/advisories/BREW-shallow-backup-CVE-2026-78677.json new file mode 100644 index 00000000000..a636f99e97a --- /dev/null +++ b/advisories/BREW-shallow-backup-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-shallow-backup-CVE-2026-78677", + "published": "2026-09-04T10:00:38Z", + "modified": "2026-09-04T10:00:38Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "shallow-backup", + "purl": "pkg:brew/shallow-backup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-shallow-backup-CVE-2026-78678.json b/advisories/BREW-shallow-backup-CVE-2026-78678.json new file mode 100644 index 00000000000..2cf6358b534 --- /dev/null +++ b/advisories/BREW-shallow-backup-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-shallow-backup-CVE-2026-78678", + "published": "2026-09-04T10:00:38Z", + "modified": "2026-09-04T10:00:38Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "shallow-backup", + "purl": "pkg:brew/shallow-backup" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-shallow-backup-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-shallow-backup-GHSA-hmq2-w58f-27jc.json index 9deb38e57ec..66a74c481df 100644 --- a/advisories/BREW-shallow-backup-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-shallow-backup-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-shallow-backup-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:34:37Z", - "modified": "2026-08-29T09:41:40Z", + "modified": "2026-09-04T10:00:38Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-shallow-backup-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-shallow-backup-GHSA-jm78-9fvv-mhgr.json index b48e35e1fa5..6fa397a8aa5 100644 --- a/advisories/BREW-shallow-backup-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-shallow-backup-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-shallow-backup-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:34:37Z", - "modified": "2026-08-29T09:41:40Z", + "modified": "2026-09-04T10:00:38Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakemake-CVE-2026-76221.json b/advisories/BREW-snakemake-CVE-2026-76221.json index a1c5397afc7..6c47380fc98 100644 --- a/advisories/BREW-snakemake-CVE-2026-76221.json +++ b/advisories/BREW-snakemake-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snakemake-CVE-2026-76221", "published": "2026-08-20T09:39:58Z", - "modified": "2026-08-28T13:18:13Z", + "modified": "2026-09-04T10:03:26Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakemake-CVE-2026-76222.json b/advisories/BREW-snakemake-CVE-2026-76222.json index 76f8c176498..5ff70ac27e5 100644 --- a/advisories/BREW-snakemake-CVE-2026-76222.json +++ b/advisories/BREW-snakemake-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snakemake-CVE-2026-76222", "published": "2026-08-20T09:39:58Z", - "modified": "2026-08-28T13:18:13Z", + "modified": "2026-09-04T10:03:26Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakemake-CVE-2026-78675.json b/advisories/BREW-snakemake-CVE-2026-78675.json new file mode 100644 index 00000000000..19a1d9b5b44 --- /dev/null +++ b/advisories/BREW-snakemake-CVE-2026-78675.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snakemake-CVE-2026-78675", + "published": "2026-09-04T10:04:58Z", + "modified": "2026-09-04T10:04:58Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snakemake", + "purl": "pkg:brew/snakemake" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.25.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-snakemake-CVE-2026-78676.json b/advisories/BREW-snakemake-CVE-2026-78676.json new file mode 100644 index 00000000000..6fd33bf3bd5 --- /dev/null +++ b/advisories/BREW-snakemake-CVE-2026-78676.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snakemake-CVE-2026-78676", + "published": "2026-09-04T10:04:58Z", + "modified": "2026-09-04T10:04:58Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snakemake", + "purl": "pkg:brew/snakemake" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.25.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-snakemake-CVE-2026-78677.json b/advisories/BREW-snakemake-CVE-2026-78677.json new file mode 100644 index 00000000000..68b83277971 --- /dev/null +++ b/advisories/BREW-snakemake-CVE-2026-78677.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snakemake-CVE-2026-78677", + "published": "2026-09-04T10:04:58Z", + "modified": "2026-09-04T10:04:58Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snakemake", + "purl": "pkg:brew/snakemake" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.25.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-snakemake-CVE-2026-78678.json b/advisories/BREW-snakemake-CVE-2026-78678.json new file mode 100644 index 00000000000..f8d6bc7879f --- /dev/null +++ b/advisories/BREW-snakemake-CVE-2026-78678.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snakemake-CVE-2026-78678", + "published": "2026-09-04T10:04:58Z", + "modified": "2026-09-04T10:04:58Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snakemake", + "purl": "pkg:brew/snakemake" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "9.25.2" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.60" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-snakemake-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-snakemake-GHSA-hmq2-w58f-27jc.json index dcb1003fa8a..522900e74b3 100644 --- a/advisories/BREW-snakemake-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-snakemake-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snakemake-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-29T09:43:05Z", + "modified": "2026-09-04T10:03:26Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snakemake-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-snakemake-GHSA-jm78-9fvv-mhgr.json index d685edad098..b16d783c6be 100644 --- a/advisories/BREW-snakemake-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-snakemake-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snakemake-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-29T09:43:05Z", + "modified": "2026-09-04T10:03:26Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.60", + "key": "pkg:pypi/gitpython@3.1.60", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-76221.json b/advisories/BREW-snowflake-cli-CVE-2026-76221.json index 065ab2e3d1a..e8ca8daf2cc 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-76221.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-76221", "published": "2026-08-20T09:40:01Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-04T10:05:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-76222.json b/advisories/BREW-snowflake-cli-CVE-2026-76222.json index 26138ad0927..41a48841640 100644 --- a/advisories/BREW-snowflake-cli-CVE-2026-76222.json +++ b/advisories/BREW-snowflake-cli-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-CVE-2026-76222", "published": "2026-08-20T09:40:01Z", - "modified": "2026-08-26T09:49:15Z", + "modified": "2026-09-04T10:05:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78675.json b/advisories/BREW-snowflake-cli-CVE-2026-78675.json new file mode 100644 index 00000000000..c3082d9d114 --- /dev/null +++ b/advisories/BREW-snowflake-cli-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snowflake-cli-CVE-2026-78675", + "published": "2026-09-04T10:05:02Z", + "modified": "2026-09-04T10:05:02Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snowflake-cli", + "purl": "pkg:brew/snowflake-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78676.json b/advisories/BREW-snowflake-cli-CVE-2026-78676.json new file mode 100644 index 00000000000..bc87c1e7070 --- /dev/null +++ b/advisories/BREW-snowflake-cli-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snowflake-cli-CVE-2026-78676", + "published": "2026-09-04T10:05:02Z", + "modified": "2026-09-04T10:05:02Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snowflake-cli", + "purl": "pkg:brew/snowflake-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78677.json b/advisories/BREW-snowflake-cli-CVE-2026-78677.json new file mode 100644 index 00000000000..98dacc503ff --- /dev/null +++ b/advisories/BREW-snowflake-cli-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snowflake-cli-CVE-2026-78677", + "published": "2026-09-04T10:05:02Z", + "modified": "2026-09-04T10:05:02Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snowflake-cli", + "purl": "pkg:brew/snowflake-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-snowflake-cli-CVE-2026-78678.json b/advisories/BREW-snowflake-cli-CVE-2026-78678.json new file mode 100644 index 00000000000..2129890bb13 --- /dev/null +++ b/advisories/BREW-snowflake-cli-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snowflake-cli-CVE-2026-78678", + "published": "2026-09-04T10:05:02Z", + "modified": "2026-09-04T10:05:02Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snowflake-cli", + "purl": "pkg:brew/snowflake-cli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-snowflake-cli-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-snowflake-cli-GHSA-hmq2-w58f-27jc.json index 615d971abce..81ff0f7c2c9 100644 --- a/advisories/BREW-snowflake-cli-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-snowflake-cli-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-29T09:45:05Z", + "modified": "2026-09-04T10:05:02Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-snowflake-cli-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-snowflake-cli-GHSA-jm78-9fvv-mhgr.json index de278be112e..9041b680af6 100644 --- a/advisories/BREW-snowflake-cli-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-snowflake-cli-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-snowflake-cli-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:35:47Z", - "modified": "2026-08-29T09:45:05Z", + "modified": "2026-09-04T10:05:02Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-standardebooks-CVE-2026-76221.json b/advisories/BREW-standardebooks-CVE-2026-76221.json index ac78029432e..a5958cfd307 100644 --- a/advisories/BREW-standardebooks-CVE-2026-76221.json +++ b/advisories/BREW-standardebooks-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-standardebooks-CVE-2026-76221", "published": "2026-08-20T09:44:27Z", - "modified": "2026-08-20T09:44:27Z", + "modified": "2026-09-04T10:10:36Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-standardebooks-CVE-2026-76222.json b/advisories/BREW-standardebooks-CVE-2026-76222.json index 89a75193111..709facb4199 100644 --- a/advisories/BREW-standardebooks-CVE-2026-76222.json +++ b/advisories/BREW-standardebooks-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-standardebooks-CVE-2026-76222", "published": "2026-08-20T09:44:27Z", - "modified": "2026-08-20T09:44:27Z", + "modified": "2026-09-04T10:10:36Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-standardebooks-CVE-2026-78675.json b/advisories/BREW-standardebooks-CVE-2026-78675.json new file mode 100644 index 00000000000..9fa18c7669b --- /dev/null +++ b/advisories/BREW-standardebooks-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-standardebooks-CVE-2026-78675", + "published": "2026-09-04T10:10:36Z", + "modified": "2026-09-04T10:10:36Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "standardebooks", + "purl": "pkg:brew/standardebooks" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.54" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-standardebooks-CVE-2026-78676.json b/advisories/BREW-standardebooks-CVE-2026-78676.json new file mode 100644 index 00000000000..c9d11bb7530 --- /dev/null +++ b/advisories/BREW-standardebooks-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-standardebooks-CVE-2026-78676", + "published": "2026-09-04T10:10:36Z", + "modified": "2026-09-04T10:10:36Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "standardebooks", + "purl": "pkg:brew/standardebooks" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.54" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-standardebooks-CVE-2026-78677.json b/advisories/BREW-standardebooks-CVE-2026-78677.json new file mode 100644 index 00000000000..897092ec8b6 --- /dev/null +++ b/advisories/BREW-standardebooks-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-standardebooks-CVE-2026-78677", + "published": "2026-09-04T10:10:36Z", + "modified": "2026-09-04T10:10:36Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "standardebooks", + "purl": "pkg:brew/standardebooks" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.54" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-standardebooks-CVE-2026-78678.json b/advisories/BREW-standardebooks-CVE-2026-78678.json new file mode 100644 index 00000000000..1df2e1fba72 --- /dev/null +++ b/advisories/BREW-standardebooks-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-standardebooks-CVE-2026-78678", + "published": "2026-09-04T10:10:36Z", + "modified": "2026-09-04T10:10:36Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "standardebooks", + "purl": "pkg:brew/standardebooks" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.54" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-standardebooks-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-standardebooks-GHSA-hmq2-w58f-27jc.json index b5b44225d0c..1020f1afa2b 100644 --- a/advisories/BREW-standardebooks-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-standardebooks-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-standardebooks-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:41:08Z", - "modified": "2026-08-29T09:50:09Z", + "modified": "2026-09-04T10:10:36Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-standardebooks-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-standardebooks-GHSA-jm78-9fvv-mhgr.json index e0746778e51..ffa240f3cc0 100644 --- a/advisories/BREW-standardebooks-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-standardebooks-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-standardebooks-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:41:08Z", - "modified": "2026-08-29T09:50:09Z", + "modified": "2026-09-04T10:10:36Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.54", + "key": "pkg:pypi/gitpython@3.1.54", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tach-CVE-2026-76221.json b/advisories/BREW-tach-CVE-2026-76221.json index 9a9f2003d26..31055364152 100644 --- a/advisories/BREW-tach-CVE-2026-76221.json +++ b/advisories/BREW-tach-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tach-CVE-2026-76221", "published": "2026-08-20T09:45:21Z", - "modified": "2026-08-20T09:45:21Z", + "modified": "2026-09-04T10:11:45Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tach-CVE-2026-76222.json b/advisories/BREW-tach-CVE-2026-76222.json index 44741004bfb..94343ca10a8 100644 --- a/advisories/BREW-tach-CVE-2026-76222.json +++ b/advisories/BREW-tach-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tach-CVE-2026-76222", "published": "2026-08-20T09:45:21Z", - "modified": "2026-08-20T09:45:21Z", + "modified": "2026-09-04T10:11:45Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tach-CVE-2026-78675.json b/advisories/BREW-tach-CVE-2026-78675.json new file mode 100644 index 00000000000..b514ef1102b --- /dev/null +++ b/advisories/BREW-tach-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tach-CVE-2026-78675", + "published": "2026-09-04T10:11:45Z", + "modified": "2026-09-04T10:11:45Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tach", + "purl": "pkg:brew/tach" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-tach-CVE-2026-78676.json b/advisories/BREW-tach-CVE-2026-78676.json new file mode 100644 index 00000000000..1950ca22a26 --- /dev/null +++ b/advisories/BREW-tach-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tach-CVE-2026-78676", + "published": "2026-09-04T10:11:45Z", + "modified": "2026-09-04T10:11:45Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tach", + "purl": "pkg:brew/tach" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-tach-CVE-2026-78677.json b/advisories/BREW-tach-CVE-2026-78677.json new file mode 100644 index 00000000000..7beda427eeb --- /dev/null +++ b/advisories/BREW-tach-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tach-CVE-2026-78677", + "published": "2026-09-04T10:11:45Z", + "modified": "2026-09-04T10:11:45Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tach", + "purl": "pkg:brew/tach" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-tach-CVE-2026-78678.json b/advisories/BREW-tach-CVE-2026-78678.json new file mode 100644 index 00000000000..740653d1c64 --- /dev/null +++ b/advisories/BREW-tach-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tach-CVE-2026-78678", + "published": "2026-09-04T10:11:45Z", + "modified": "2026-09-04T10:11:45Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tach", + "purl": "pkg:brew/tach" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-tach-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-tach-GHSA-hmq2-w58f-27jc.json index a2da37df22c..fcbba4bf315 100644 --- a/advisories/BREW-tach-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-tach-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tach-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:42:17Z", - "modified": "2026-08-29T09:51:16Z", + "modified": "2026-09-04T10:11:45Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tach-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-tach-GHSA-jm78-9fvv-mhgr.json index 3c64a69ccb8..e18d200e310 100644 --- a/advisories/BREW-tach-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-tach-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tach-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:42:17Z", - "modified": "2026-08-29T09:51:16Z", + "modified": "2026-09-04T10:11:45Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-76221.json b/advisories/BREW-tartufo-CVE-2026-76221.json index f9d987aa29a..23b1f25a41b 100644 --- a/advisories/BREW-tartufo-CVE-2026-76221.json +++ b/advisories/BREW-tartufo-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76221", "published": "2026-08-20T09:45:22Z", - "modified": "2026-08-20T09:45:22Z", + "modified": "2026-09-04T10:12:20Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-76222.json b/advisories/BREW-tartufo-CVE-2026-76222.json index 654d8d72fbb..cdd41d21741 100644 --- a/advisories/BREW-tartufo-CVE-2026-76222.json +++ b/advisories/BREW-tartufo-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-CVE-2026-76222", "published": "2026-08-20T09:45:22Z", - "modified": "2026-08-20T09:45:22Z", + "modified": "2026-09-04T10:12:20Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-CVE-2026-78675.json b/advisories/BREW-tartufo-CVE-2026-78675.json new file mode 100644 index 00000000000..82a37e2e095 --- /dev/null +++ b/advisories/BREW-tartufo-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tartufo-CVE-2026-78675", + "published": "2026-09-04T10:12:20Z", + "modified": "2026-09-04T10:12:20Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tartufo", + "purl": "pkg:brew/tartufo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-tartufo-CVE-2026-78676.json b/advisories/BREW-tartufo-CVE-2026-78676.json new file mode 100644 index 00000000000..d4070e4ec4c --- /dev/null +++ b/advisories/BREW-tartufo-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tartufo-CVE-2026-78676", + "published": "2026-09-04T10:12:20Z", + "modified": "2026-09-04T10:12:20Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tartufo", + "purl": "pkg:brew/tartufo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-tartufo-CVE-2026-78677.json b/advisories/BREW-tartufo-CVE-2026-78677.json new file mode 100644 index 00000000000..0e8fe641570 --- /dev/null +++ b/advisories/BREW-tartufo-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tartufo-CVE-2026-78677", + "published": "2026-09-04T10:12:20Z", + "modified": "2026-09-04T10:12:20Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tartufo", + "purl": "pkg:brew/tartufo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-tartufo-CVE-2026-78678.json b/advisories/BREW-tartufo-CVE-2026-78678.json new file mode 100644 index 00000000000..a4cfa94a8b4 --- /dev/null +++ b/advisories/BREW-tartufo-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tartufo-CVE-2026-78678", + "published": "2026-09-04T10:12:20Z", + "modified": "2026-09-04T10:12:20Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tartufo", + "purl": "pkg:brew/tartufo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.58" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-tartufo-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-tartufo-GHSA-hmq2-w58f-27jc.json index 9a739e28a17..72b5fd95010 100644 --- a/advisories/BREW-tartufo-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-tartufo-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:42:18Z", - "modified": "2026-08-29T09:51:56Z", + "modified": "2026-09-04T10:12:20Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tartufo-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-tartufo-GHSA-jm78-9fvv-mhgr.json index 795392f3972..ed3533afc8c 100644 --- a/advisories/BREW-tartufo-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-tartufo-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tartufo-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:42:18Z", - "modified": "2026-08-29T09:51:56Z", + "modified": "2026-09-04T10:12:20Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -41,6 +42,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.58", + "key": "pkg:pypi/gitpython@3.1.58", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tern-CVE-2026-76221.json b/advisories/BREW-tern-CVE-2026-76221.json index 72adaaacd23..efc9308995f 100644 --- a/advisories/BREW-tern-CVE-2026-76221.json +++ b/advisories/BREW-tern-CVE-2026-76221.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tern-CVE-2026-76221", "published": "2026-08-20T09:45:59Z", - "modified": "2026-08-20T09:45:59Z", + "modified": "2026-09-04T10:12:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tern-CVE-2026-76222.json b/advisories/BREW-tern-CVE-2026-76222.json index 9cb112edba0..18ee8022a4b 100644 --- a/advisories/BREW-tern-CVE-2026-76222.json +++ b/advisories/BREW-tern-CVE-2026-76222.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tern-CVE-2026-76222", "published": "2026-08-20T09:45:59Z", - "modified": "2026-08-20T09:45:59Z", + "modified": "2026-09-04T10:12:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tern-CVE-2026-78675.json b/advisories/BREW-tern-CVE-2026-78675.json new file mode 100644 index 00000000000..df79f6d30bc --- /dev/null +++ b/advisories/BREW-tern-CVE-2026-78675.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tern-CVE-2026-78675", + "published": "2026-09-04T10:12:29Z", + "modified": "2026-09-04T10:12:29Z", + "upstream": [ + "PYSEC-2026-3785", + "CVE-2026-78675", + "GHSA-7833-fr7j-v32q" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tern", + "purl": "pkg:brew/tern" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.45" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q" + } + ] +} diff --git a/advisories/BREW-tern-CVE-2026-78676.json b/advisories/BREW-tern-CVE-2026-78676.json new file mode 100644 index 00000000000..7ff39a083ec --- /dev/null +++ b/advisories/BREW-tern-CVE-2026-78676.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tern-CVE-2026-78676", + "published": "2026-09-04T10:12:29Z", + "modified": "2026-09-04T10:12:29Z", + "upstream": [ + "PYSEC-2026-3786", + "CVE-2026-78676", + "GHSA-284h-m62q-gf8w" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tern", + "purl": "pkg:brew/tern" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.45" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w" + } + ] +} diff --git a/advisories/BREW-tern-CVE-2026-78677.json b/advisories/BREW-tern-CVE-2026-78677.json new file mode 100644 index 00000000000..b5e00ea56e0 --- /dev/null +++ b/advisories/BREW-tern-CVE-2026-78677.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tern-CVE-2026-78677", + "published": "2026-09-04T10:12:29Z", + "modified": "2026-09-04T10:12:29Z", + "upstream": [ + "PYSEC-2026-3787", + "CVE-2026-78677", + "GHSA-8mcc-hrx5-hvxc" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tern", + "purl": "pkg:brew/tern" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.45" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + } + ] + }, + "details": "GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-8mcc-hrx5-hvxc" + } + ] +} diff --git a/advisories/BREW-tern-CVE-2026-78678.json b/advisories/BREW-tern-CVE-2026-78678.json new file mode 100644 index 00000000000..e8664c85b0a --- /dev/null +++ b/advisories/BREW-tern-CVE-2026-78678.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-tern-CVE-2026-78678", + "published": "2026-09-04T10:12:29Z", + "modified": "2026-09-04T10:12:29Z", + "upstream": [ + "PYSEC-2026-3788", + "CVE-2026-78678", + "GHSA-5xxx-qhh7-9287" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "tern", + "purl": "pkg:brew/tern" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "3.1.59", + "resource": "gitpython", + "resource_purl": "pkg:pypi/gitpython@3.1.45" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + } + ] + }, + "details": "GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame" + }, + { + "type": "EVIDENCE", + "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287" + } + ] +} diff --git a/advisories/BREW-tern-GHSA-hmq2-w58f-27jc.json b/advisories/BREW-tern-GHSA-hmq2-w58f-27jc.json index 62e706bdabf..569625ba974 100644 --- a/advisories/BREW-tern-GHSA-hmq2-w58f-27jc.json +++ b/advisories/BREW-tern-GHSA-hmq2-w58f-27jc.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tern-GHSA-hmq2-w58f-27jc", "published": "2026-08-13T17:43:04Z", - "modified": "2026-08-29T09:52:04Z", + "modified": "2026-09-04T10:12:29Z", "upstream": [ "GHSA-hmq2-w58f-27jc", - "CVE-2026-76222" + "CVE-2026-76222", + "PYSEC-2026-3784" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI", diff --git a/advisories/BREW-tern-GHSA-jm78-9fvv-mhgr.json b/advisories/BREW-tern-GHSA-jm78-9fvv-mhgr.json index 1163b9735a1..85e020b210b 100644 --- a/advisories/BREW-tern-GHSA-jm78-9fvv-mhgr.json +++ b/advisories/BREW-tern-GHSA-jm78-9fvv-mhgr.json @@ -2,10 +2,11 @@ "schema_version": "1.7.3", "id": "BREW-tern-GHSA-jm78-9fvv-mhgr", "published": "2026-08-13T17:43:04Z", - "modified": "2026-08-29T09:52:04Z", + "modified": "2026-09-04T10:12:29Z", "upstream": [ "GHSA-jm78-9fvv-mhgr", - "CVE-2026-76221" + "CVE-2026-76221", + "PYSEC-2026-3783" ], "affected": [ { @@ -38,6 +39,14 @@ "strategy": "registry", "confidence": "high", "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "gitpython", + "subject_version": "3.1.45", + "key": "pkg:pypi/gitpython@3.1.45", + "resource": "gitpython" + }, { "strategy": "registry", "ecosystem": "PyPI",