What is CVE-2026-47191?
CVE-2026-47191 was discovered in 'kas', a setup tool for bitbake-based projects. In versions prior to 5.3, when relying solely on a git commit ID for repository verification, users may be tricked into checking out an unvalidated branch. Users are advised to upgrade to version 5.3 or later.
Azərbaycanca: CVE-2026-47191, bitbake əsaslı layihələr üçün istifadə olunan 'kas' quraşdırma alətində aşkarlanmışdır. 5.3 versiyasından əvvəlki versiyalarda, yalnız git commit ID-si ilə repozitoriyanın təhlükəsizliyini yoxlamağa güvənən istifadəçilər, təsdiqlənməmiş branch-ə keçid etməyə aldadıla bilərlər. İstifadəçilərə 5.3 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
FAQ2
Which versions of the 'kas' tool are affected by CVE-2026-47191?
CVE-2026-47191 affects versions of the 'kas' tool prior to 5.3.
What should users do to protect against CVE-2026-47191?
Users are advised to upgrade the 'kas' tool to version 5.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.