Git Repository Integrity Vulnerability in kas by Siemens
CVE-2026-47191
2.1LOW
What is CVE-2026-47191?
The kas tool for bitbake projects is susceptible to a security flaw that allows attackers to potentially manipulate Git repository checkouts using identical branch names. Prior to version 5.3, kas relied on commit IDs (SHA-1 or SHA-256) for validating repository states, which could mislead users into checking out branches that have been compromised. This vulnerability particularly affects SHA-256 commit IDs, which are critical for secure validation. Users are advised to implement alternative validation measures such as utilizing cryptographically signed commits or tags. As a best practice, mirroring repositories and validating their integrity should be considered to mitigate risks associated with malicious third-party control.
Affected Version(s)
kas < 5.3