CVE-2026-44971
Last modified
CVE-2026-44971 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. This allows an attacker who can influence the scanned repository URL to trigger SSRF and capture the GH_TOKEN used by GuardDog. This vulnerability is fixed in .
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-44971?
How severe is CVE-2026-44971?
How do I fix CVE-2026-44971?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-44966Velocity.js is a JavaScript implementation of the Apache Vel…9.8
- CVE-2026-44967OpenTelemetry-cpp is the C++ implementation of OpenTelemetry…5.3
- CVE-2026-44968dbt-mcp is a Model Context Protocol server for interacting w…6.3
- CVE-2026-44969dbt-mcp is a Model Context Protocol server for interacting w…3.3
- CVE-2026-4497A vulnerability was determined in Totolink WA300 5.2cu.7112_…9.8
- CVE-2026-44970dbt-mcp is a Model Context Protocol server for interacting w…4.3
- CVE-2026-44972GuardDog is a CLI tool to identify malicious PyPI packages. …5
- CVE-2026-44973Billy is an interface filesystem abstraction for Go. Prior t…8.1
- CVE-2026-44974@hapi/content provided HTTP Content-* headers parsing. Prior…7.7
- CVE-2026-44975Frappe is a full-stack web application framework. Prior to v…5.3
- CVE-2026-44976Frappe is a full-stack web application framework. Prior to v…5.3
- CVE-2026-44978xrdp is an open source RDP server. Versions 0.10.6 and prior…5.3
Are you affected by CVE-2026-44971?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
