{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/gitingest/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gitingest:gitingest:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-82289"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Gitingest (\u003c= 0.3.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","credential-theft","data-exfiltration"],"_cs_type":"advisory","_cs_vendors":["Gitingest"],"content_html":"\u003cp\u003eGitingest versions 0.3.1 and earlier contain a security vulnerability in the _validate_host function. The implementation improperly validates hostnames by only checking for the presence of 'git.', 'gitlab.', or 'github.' prefixes. This flaw allows an attacker to bypass intended restrictions against a known-hosts list, enabling the application to make outbound HTTP requests to attacker-controlled infrastructure. By directing the application to a malicious host, an attacker can capture GitHub personal access tokens (PATs) that are inadvertently transmitted as HTTP basic credentials during the outbound request process. This vulnerability poses a significant risk to organizations using Gitingest to process repository data, as it leads to the compromise of credentials and potential unauthorized access to protected GitHub resources.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to steal GitHub personal access tokens, potentially leading to unauthorized access, repository cloning, or code manipulation within the victim's GitHub organization. The vulnerability affects all users running Gitingest version 0.3.1 or earlier, with no specific OS constraints.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Gitingest to a version later than 0.3.1 as soon as a patch is made available by the maintainers.\u003c/li\u003e\n\u003cli\u003eAudit egress traffic logs for unexpected connections originating from servers hosting Gitingest to unauthorized or unknown external domains.\u003c/li\u003e\n\u003cli\u003eRotate any GitHub personal access tokens that may have been configured within, or accessed by, vulnerable Gitingest instances.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering at the network level to restrict the Gitingest application host to only communicate with legitimate and required GitHub API endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:41:08Z","date_published":"2026-08-28T21:41:08Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gitingest-cve-2026-82289/","summary":"Gitingest versions 0.3.1 and earlier contain a hostname validation vulnerability allowing attackers to force outbound connections and exfiltrate GitHub personal access tokens.","title":"Improper Hostname Validation in Gitingest","url":"https://feed.craftedsignal.io/briefs/2026-08-gitingest-cve-2026-82289/"}],"language":"en","title":"CraftedSignal Threat Feed - Gitingest","version":"https://jsonfeed.org/version/1.1"}