Git Repository Integrity Vulnerability in kas by Siemens
CVE-2026-47191

2.1LOW

Key Information:

Vendor

Siemens

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-47191?

The kas tool for bitbake projects is susceptible to a security flaw that allows attackers to potentially manipulate Git repository checkouts using identical branch names. Prior to version 5.3, kas relied on commit IDs (SHA-1 or SHA-256) for validating repository states, which could mislead users into checking out branches that have been compromised. This vulnerability particularly affects SHA-256 commit IDs, which are critical for secure validation. Users are advised to implement alternative validation measures such as utilizing cryptographically signed commits or tags. As a best practice, mirroring repositories and validating their integrity should be considered to mitigate risks associated with malicious third-party control.

Affected Version(s)

kas < 5.3

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.