WhisperX tag archive

#CVE-2026-24137

This page collects WhisperX intelligence signals tagged #CVE-2026-24137. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-25 07:52:17 · GitHub Issues

1. Sigstore TUF Client Vulnerability (CVE-2026-24137): Path Traversal Flaw Allows Arbitrary File Writes

A critical security flaw has been identified in the legacy TUF client within the widely-used Sigstore software supply chain security project. The vulnerability, tracked as CVE-2026-24137, allows for arbitrary file writes via a path traversal attack. The core failure is in the client's file caching mechanism, which cons...

The Lab · 2026-04-06 02:27:02 · GitHub Issues

2. Sigstore TUF Client Vulnerability (CVE-2026-24137) Exposes Systems to Arbitrary File Writes

A critical path traversal vulnerability in Sigstore's legacy TUF client has been disclosed, enabling attackers to perform arbitrary file writes on affected systems. The flaw, tracked as CVE-2026-24137 (GHSA-fcv2-xgw5-pqxf), resides within the `github.com/sigstore/sigstore` package and stems from improper handling of ta...