Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

CVE-2026-78136: CHIRP radio program can be tricked to run code

CVE-2026-78136 · published 12 days ago
Summary

Versions of the CHIRP radio utility released before a recent update will execute code hidden in specially crafted CSV files. If a user opens such a file, an attacker could run unwanted programs or steal information on the computer. Upgrade CHIRP to the latest version and only open CSV files from trusted sources.

What to do
  • Update chirpmyradio chirp to version 39178dbfc4fece083ab9ed20286d6ae3a91a718e or later.
Affected software
VendorProductAffected versions
chirpmyradio chirp < 39178dbfc4fece083ab9ed20286d6ae3a91a718e
Original advisory text
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.
Severity
7.8 High
CVSS 3.1: 7.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Timeline
Published23 Aug 2026
Updated24 Aug 2026
First seen23 Aug 2026
Sources
CVE-2026-78136 · MITRE
Monitor software like this
Free during beta