


Perceptive Security
SOC/SIEM Consultancy

GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repo…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 16:03:27
Source:
nvd.nist.gov
Security Tools, Supply Chain & Dependencies
GuardDog CLI tool for identifying malicious PyPI packages contains a Server-Side Request Forgery (SSRF) vulnerability in versions 1.0.0 to 2.9.0. The vulnerability occurs in the programmatic remote project scanning path where attacker-controlled repository URLs are processed using blind string replacement. This allows attackers to manipulate repository URLs and capture GitHub credentials (GH_TOKEN) sent with the resulting requests. The vulnerability enables credential theft through SSRF attacks when scanning remote projects.
Technical details
Mitigation steps:
Affected products:
GuardDog
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44971
https://github.com/DataDog/guarddog/security/advisories/GHSA-587r-mc96-6f2p
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
