CVE-2026-44971
Last modified
CVE-2026-44971 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. This allows an attacker who can influence the scanned repository URL to trigger SSRF and capture the GH_TOKEN used by GuardDog. This vulnerability is fixed in .
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-44971?
How severe is CVE-2026-44971?
How do I fix CVE-2026-44971?
Are you affected by CVE-2026-44971?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
