PT-2026-46879 · Kas · Kas

Published

2026-06-01

·

Updated

2026-06-04

·

CVE-2026-47192

CVSS v4.0

2.1

Low

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions kas versions prior to 5.3
Description The software processes repository configuration includes before validating the signatures of those repositories. Under specific conditions, an attacker who has gained control of a referenced repository can replace the original repository with one under their control. This occurs if the victim's configuration includes a file from the attacked repository, the repository state is referenced by a tag without a commit ID, the validation key is stored as a file in a repository without a specified fingerprint, and the source dir variable is not set. In this scenario, the attacker can modify the included configuration to replace the tag signature validation key with a key of their choosing.
Recommendations Update to version 5.3. Pin the expected signature key via its fingerprint when storing it as a file in a repository.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2026-47192
GHSA-4VQC-WPWG-VH7J

Affected Products

Kas