CVE-2026-47192: CWE-347: Improper Verification of Cryptographic Signature in siemens kas
kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signatures of those repositories. This may allow to replace on original repository with one under the control of an attacker under very specific conditions. First of all, the attacker must have gained control of a repository that a kas file of the victim is referencing. Furthermore, the following conditions must be fulfilled: the victim's kas configuration must include a configuration file from the attacked repository; the repository state is referenced by tag, and no commit ID is specified (this is triggering a warning, though); the key used for validating the tag or commit signature is stored as file in a repository; no fingerprint for the key is specified; and the `_source_dir` key must not be set by the victim when calling kas (e.g. by avoiding a local `.config.yaml`). Given these conditions, the attacker could modify the included kas configuration in way that the key used to validate the tag signature of the attacker's repository could be replaced by an attacker-chosen key. No other exploit possibilities have been identified so far, but this does not rule out that those may exist. All patches have been released along with kas version 5.3. As a workaround, pin the expected signature key via its fingerprint, also when storing it as file in a repository.
AI Analysis
Technical Summary
The kas tool for bitbake-based projects, starting from version 4.8 and prior to 5.3, improperly verifies cryptographic signatures by processing repository configurations before signature validation. This can allow an attacker who controls a referenced repository and meets several specific conditions—such as the victim's kas configuration including a file from the attacker-controlled repository, referencing repository state by tag without commit ID, storing the key as a file without specifying a fingerprint, and not setting the _source_dir key—to replace the original repository with a malicious one. No other exploitation methods are currently identified. The vulnerability is addressed in kas version 5.3, and pinning the signature key by fingerprint is advised as a workaround.
Potential Impact
An attacker with control over a repository referenced by a victim's kas configuration could replace the original repository with a malicious one under very specific conditions. This could lead to the victim unknowingly processing attacker-controlled configuration files. The impact is limited by the complexity of required conditions and the low CVSS score (2.1), indicating low severity.
Mitigation Recommendations
A fix is available in kas version 5.3. Users should upgrade to version 5.3 or later to remediate this vulnerability. As a workaround, users can pin the expected signature key by its fingerprint even when the key is stored as a file in a repository. This prevents the attacker from substituting the key used for signature validation. No other mitigations are specified.
CVE-2026-47192: CWE-347: Improper Verification of Cryptographic Signature in siemens kas
Description
kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signatures of those repositories. This may allow to replace on original repository with one under the control of an attacker under very specific conditions. First of all, the attacker must have gained control of a repository that a kas file of the victim is referencing. Furthermore, the following conditions must be fulfilled: the victim's kas configuration must include a configuration file from the attacked repository; the repository state is referenced by tag, and no commit ID is specified (this is triggering a warning, though); the key used for validating the tag or commit signature is stored as file in a repository; no fingerprint for the key is specified; and the `_source_dir` key must not be set by the victim when calling kas (e.g. by avoiding a local `.config.yaml`). Given these conditions, the attacker could modify the included kas configuration in way that the key used to validate the tag signature of the attacker's repository could be replaced by an attacker-chosen key. No other exploit possibilities have been identified so far, but this does not rule out that those may exist. All patches have been released along with kas version 5.3. As a workaround, pin the expected signature key via its fingerprint, also when storing it as file in a repository.
CVSS v4.0
Score 2.1low
Affected software
siemens
kas
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The kas tool for bitbake-based projects, starting from version 4.8 and prior to 5.3, improperly verifies cryptographic signatures by processing repository configurations before signature validation. This can allow an attacker who controls a referenced repository and meets several specific conditions—such as the victim's kas configuration including a file from the attacker-controlled repository, referencing repository state by tag without commit ID, storing the key as a file without specifying a fingerprint, and not setting the _source_dir key—to replace the original repository with a malicious one. No other exploitation methods are currently identified. The vulnerability is addressed in kas version 5.3, and pinning the signature key by fingerprint is advised as a workaround.
Potential Impact
An attacker with control over a repository referenced by a victim's kas configuration could replace the original repository with a malicious one under very specific conditions. This could lead to the victim unknowingly processing attacker-controlled configuration files. The impact is limited by the complexity of required conditions and the low CVSS score (2.1), indicating low severity.
Mitigation Recommendations
A fix is available in kas version 5.3. Users should upgrade to version 5.3 or later to remediate this vulnerability. As a workaround, users can pin the expected signature key by its fingerprint even when the key is stored as a file in a repository. This prevents the attacker from substituting the key used for signature validation. No other mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-18T22:07:37.435Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7f4ccfbf8831d53972218f
Added to database: 08/14/2026, 17:13:51 UTC
Last enriched: 08/14/2026, 17:31:19 UTC
Last updated: 09/28/2026, 13:47:45 UTC
Views: 67
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.