Listen to this Post
The mentioned vulnerability revolves around missing or incomplete cryptographically sound integrity enforcement during component archive downloads and execution phases within the SBOM scanner workflow. In early alpha builds, automated update mechanisms or optional dependency fetchers (such as external Syft binaries or helper utilities) failed to enforce strict SHA-256 digest validation and signed provenance checks prior to execution. As a consequence, a local or network-based attacker capable of executing a man-in-the-middle (MitM) attack or poisoning a local cache directory could potentially substitute downstream binary archives with altered payloads. Without mandatory digest verification, the scanner process executes the modified binary within the user’s execution context. Later software releases resolve this by enforcing upstream digest verification before execution, pinning binary checksums, ensuring explicit user consent, and requiring signed release provenance via public bundles, preventing execution of unauthorized or unverified components.
DailyCVE Form:
Platform: Linux, npm, Python
Version: v0.1.0-alpha.1 to v0.7.0-alpha.2
Vulnerability: Unverified Digest Execution
Severity: Low
date: 07-10-2026
Prediction: Fixed in v0.8.0-alpha.2
What Undercode Say:
Analytics
Verify release archive SHA-256 digest before execution echo "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 awarely-scan" | sha256sum --check Inspect downloaded release provenance and sign validation using GitHub CLI gh attestation verify awarely-scan --repo awarelyeu/awarely-sbom-scanner Execute guided scan while preventing automatic tool installation ./awarely-scan guided --offline
Exploit: (Educational Purposes!)
Example showing exploitation of missing digest verification via binary spoofing in cache mkdir -p /tmp/awarely-cache/ cp /bin/malicious_payload /tmp/awarely-cache/syft Unverified scanner execution invoking spoofed local cache binary ./awarely-scan --use-cached-syft
Protection:
Upgrade Awarely Scan to fixed version v0.8.0-alpha.2 or later curl -sSL https://github.com/awarelyeu/awarely-sbom-scanner/releases/download/v0.8.0-alpha.2/install.sh | bash Ensure explicit verification of downloaded release archives via checksum sha256sum -c awarely-scan.sha256
Impact:
The vulnerability allows local or network-positioned attackers to replace unverified helper binaries with malicious software, potentially executing arbitrary code with the permissions of the user running the SBOM scan.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

