{"id":"CVE-2026-47191","summary":"kas checks out SHA-like git branches as valid commits","details":"kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked to check out a branch of the same name from this repository. This implies that the referenced repository has been taken over by an attacker and modified to carry such a branch. SHA-1 commits may also be replaced by creating hash collisions, so the primary impact of this issue is on SHA-256 commit IDs. Version 5.3 fixes the issue. As a workaround, avoid relying solely on the commit ID for integrity validation of a repository that might become under control of a malicious 3rd party. If available, additional validate cryptographically signed commits or tags. Alternatively, mirror the repository to a save place, validate its integrity, and use this instead of the original one.","aliases":["GHSA-qjwp-hrq6-r26r","PYSEC-2026-2544"],"modified":"2026-08-19T03:31:18.786894469Z","published":"2026-08-14T16:35:48.128Z","database_specific":{"cwe_ids":["CWE-347"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47191.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47191.json"},{"type":"ADVISORY","url":"https://github.com/pypa/advisory-database/tree/main/vulns/kas/PYSEC-2026-2544.yaml"},{"type":"ADVISORY","url":"https://github.com/siemens/kas/security/advisories/GHSA-qjwp-hrq6-r26r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47191"},{"type":"FIX","url":"https://github.com/siemens/kas/commit/4cb4a3d01122ffaec9feaae768a5814092f6f9b5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/siemens/kas","events":[{"introduced":"0"},{"fixed":"4cb4a3d01122ffaec9feaae768a5814092f6f9b5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"5.3"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["5.2","5.1","5.0","4.8.2","4.8.1","4.8","4.7","4.6","4.5","4.4","4.3.2","4.3.1","4.3","4.2","4.1","4.0","3.3","3.2.3","3.2.2","3.2.1","3.2","3.1","3.0.2","3.0.1","3.0","2.6.3","2.6.2","2.6.1","2.6","2.5","2.4","2.3.3","2.3.2","2.3.1","2.3","2.2","2.1.1","2.1","2.0","1.1","1.0","0.20.1","0.20.0","0.19.0","0.18.0","0.17.0","0.16.1","0.16.0","0.15.0","0.14.0","0.13.0","0.12.0","0.11.0","0.10.0","0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47191.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}