CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-24480: QGIS affected git revisions

CVE-2026-24480. EPSS 0.00444 (percentile 0.36394), scored 2026-10-05.

Affected technology

QGIS · < 76a693cd91650f9b4e83edac525e5e4f90d954e9
qgis

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

The source says if these workflows then checked out and executed code from the head of an external pull request (which could have been attacker controlled), the attacker could have executed arbitrary commands with elevated privileges. Vendor/CNA’s CVSS 4.0 assessment (base score 8.7/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-863
CCR priority
0.1 /100 (P5)
EPSS
0.00444 · percentile 0.36489 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-24480.html