{"api_version":"v1","generated_at":"2026-10-06T23:30:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-misp-misp-modules-a1daca3230c6","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"misp-modules","next_cursor":null,"observations":[{"affected":"misp-modules: \u2264 3.0.10","affected_versions_present":true,"cve_id":"CVE-2026-97863","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-97863","fixed":"All user-controlled and configuration values interpolated into the generated shell script are now passed through Python's shlex.quote() function, which produces a safely quoted string that cannot be broken out of by embedded shell metacharacters. For the JSON access-rule block that embeds multiple attribute values within a single shell assignment, the JSON content is first assembled as plain text and then the entire assembled string is shlex-quoted once, preventing stray quote characters from corrupting the outer quoting. The 'config' variable is now initialized to an empty dictionary before the conditional assignment, eliminating the NameError.","last_modified":"2026-09-25T13:19:52.508Z","patch_url":"https://github.com/misp/misp-modules/commit/625b54908efbd6acc8343aa3370d401dd370e748","primary_source":"","published":"2026-09-25T08:03:24.441Z"},{"affected":"\u2264 v3.0.8","affected_versions_present":true,"cve_id":"CVE-2026-62143","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62143","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-14T14:32:41.437Z","patch_url":"","primary_source":"","published":"2026-07-13T07:52:08.643Z"},{"affected":"< 3.0.7","affected_versions_present":true,"cve_id":"CVE-2026-44363","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44363","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T12:31:25.989Z","patch_url":"","primary_source":"","published":"2026-05-13T19:16:59.579Z"},{"affected":"<= 3.0.7","affected_versions_present":true,"cve_id":"CVE-2026-44364","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44364","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T19:52:33.469Z","patch_url":"","primary_source":"","published":"2026-05-13T19:15:03.368Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"misp"}}
