Code Injection Vulnerability in CHIRP by ChirpMyRadio
CVE-2026-78136
7.8HIGH
What is CVE-2026-78136?
A code injection vulnerability exists in CHIRP, a popular radio programming tool, allowing attackers to exploit the software through crafted CSV data. The issue occurs within the _clean_tmode function in drivers/kenwood_itm.py. When malicious CSV input is processed, it enables unauthorized code execution, posing significant security risks to affected users and systems.
Affected Version(s)
CHIRP 0 < 39178dbfc4fece083ab9ed20286d6ae3a91a718e
