← Späť na vyhľadávanie CVE

CVE-2026-44971

GuardDog

Popis

GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller-s GitHub credentials with the resulting request. This allows an attacker who can influence the scanned repository URL to trigger SSRF and capture the GH_TOKEN used by GuardDog. This vulnerability is fixed in .

CVSS 8.2EPSS 0.198%Riziko 0.83
Zobraziť zdroj
Zverejnené
2026-05-27 15:16:29
Dotknuté verzie
>=1.0.0,<2.9.0
Typ
Package
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N