PT-2026-46879 · Kas · Kas
Published
2026-06-01
·
Updated
2026-06-04
·
CVE-2026-47192
CVSS v4.0
2.1
Low
| Vector | AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
kas versions prior to 5.3
Description
The software processes repository configuration includes before validating the signatures of those repositories. Under specific conditions, an attacker who has gained control of a referenced repository can replace the original repository with one under their control. This occurs if the victim's configuration includes a file from the attacked repository, the repository state is referenced by a tag without a commit ID, the validation key is stored as a file in a repository without a specified fingerprint, and the
source dir variable is not set. In this scenario, the attacker can modify the included configuration to replace the tag signature validation key with a key of their choosing.Recommendations
Update to version 5.3.
Pin the expected signature key via its fingerprint when storing it as a file in a repository.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kas