Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:brew/snowflake-cli

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-78679 is a vulnerability in GitPython's TagReference.create() method where a positional 'reference' argument can bypass the intended guard against unsafe '--file' options. This allows an attacker controlling the 'reference' parameter to cause an arbitrary local file read, with the file contents returned as the annotated tag message. The issue is an incomplete fix of a prior vulnerability and affects GitPython versions up to 3.1.58. A patch is available to properly include positional arguments in the unsafe option checks or to separate positional arguments from options.

Join the discussion

CVE-2026-78676 is a critical vulnerability in GitPython's GitConfigParser affecting versions >=3.4.1 <3.27.0. It arises from improper handling of multi-line git config values during read and rewrite cycles, causing dormant multi-line values to be corrupted into active injected directives such as core.hooksPath. This can lead to arbitrary code execution when GitPython writes back the config file, enabling attackers to inject malicious hook paths.

Join the discussion

CVE-2026-78675 is a high-severity vulnerability in GitPython used by Snowflake CLI, allowing arbitrary local file content disclosure via the [include] directive in an untrusted .gitmodules file. The issue arises because the SubmoduleConfigParser does not disable merge_includes when parsing .gitmodules, which is attacker-controlled. This allows an attacker to craft a .gitmodules file that includes arbitrary local files, causing the parser to read and expose the first line of those files in exception messages. The vulnerability affects versions >=3.4.1 and <3.27.0 of Snowflake CLI. A patch is available to address this issue.

Join the discussion

CVE-2026-78677 is a high-severity vulnerability in GitPython used by snowflake-cli, where the clone_from() and clone() methods omit the --separate-git-dir option from their unsafe options denylist. This omission allows an attacker to specify an arbitrary path for the .git metadata directory outside the intended clone destination, enabling arbitrary directory and file creation controlled by the attacker within the filesystem permissions of the running process. The flaw arises from a denylist parity gap between clone and init commands, despite documentation stating the option should be blocked by default. A fix is available for affected versions.

Join the discussion

A vulnerability in GitPython used by snowflake-cli allows an attacker to read arbitrary local files via the Repo.blame() or Repo.blame_incremental() methods. The issue arises because the denylist for unsafe git revision options only blocks file-write options (--output/-o) but omits file-read options (--contents/-S). This omission enables an attacker to supply a crafted revision argument that causes git blame to include contents of arbitrary files in its output. The vulnerability affects GitPython versions from 3.4.1 up to but not including 3.27.0. A fix is available to address this issue.

Join the discussion

A vulnerability in GitPython used by snowflake-cli allows bypassing the unsafe git option guard via a crafted short-option token with split_single_char_options set to false. This enables arbitrary OS command execution through git's --upload-pack option when forwarding user-controlled kwargs to guarded methods like clone or fetch. The issue affects GitPython versions from 3.4.1 up to but not including 3.25.0. A patch is available to fix this bypass.

Join the discussion

CVE-2026-76217 is a vulnerability in the Snowflake CLI's use of GitPython where the methods IndexFile.remove() and Head.checkout() forward arbitrary keyword arguments to git commands without proper validation. By passing the flags --pathspec-from-file together with --pathspec-file-nul, an attacker can cause Git to treat the entire contents of a chosen file as a single pathspec. When the pathspec does not match any files, Git returns an error message that includes the entire file content verbatim in stderr, which GitPython surfaces through GitCommandError.stderr. This results in an arbitrary file read vulnerability. The issue affects Snowflake CLI versions from 3.4.1 up to but not including 3.25.0. A patch is available to address this vulnerability. The CVSS 3.1 score is 6.5 (medium severity).

Join the discussion

GitPython's Repo.init method forwards all keyword arguments directly to git init without guarding unsafe options. This allows an attacker who can control the 'template' argument to plant malicious git hooks that execute arbitrary code during subsequent git operations. The vulnerability affects GitPython versions from 3.4.1 up to but not including 3.25.0. The attack requires the attacker to stage an executable hook directory at a known path and have the application call Repo.init with a crafted template argument. A patch is available that adds a guard against unsafe options like --template.

Join the discussion

GitPython's IndexFile methods from_tree, reset, and merge_tree allow an attacker to overwrite arbitrary files by injecting unsafe git read-tree options. These methods append caller-controlled treeish strings to git read-tree without guarding against unsafe options or using a '--' separator. This enables an attacker to specify the --index-output option to write a valid git-index blob to any file path writable by the host process, causing file corruption or destruction. The vulnerability affects GitPython versions >=3.4.1 and <3.25.0 and has a CVSS score of 8.1 (high severity). A patch is available to add unsafe option checks and proper argument separation.

Join the discussion

GitPython versions up to 3.1.57 contain a vulnerability in the config-name validator that allows injection of arbitrary git configuration directives via crafted option names. This flaw permits an attacker to forge directives such as core.sshCommand or core.hooksPath, leading to remote code execution on subsequent git operations. The issue arises because the validator does not reject characters like '=', '#', or whitespace in option names, allowing malicious input to be written verbatim into the config file. This vulnerability affects applications embedding GitPython that forward attacker-controlled option names to the config writer.

Join the discussion

Showing 1 to 10 of 28 results

Filters:Package: pkg:brew/snowflake-cli
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses