<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – dbt Core</title>
  <link>https://cvedaily.com/pages/tags/dbt-core.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/dbt-core.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – dbt Core</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-29790 – dbt-common is the shared common utilities for dbt-core and adapter implementatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29790</guid>
    <pubDate>Fri, 06 Mar 2026 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-29790</strong></p>
  <p>dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.37.3, a path traversal vulnerability exists in dbt-common's safe_extract() function used when extracting tarball archives. The function uses os.path.commonprefix() to validate that extracted files remain within the intended destination directory. However, commonprefix() compares…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36105 – dbt enables data analysts and engineers to transform their data using the same p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36105</guid>
    <pubDate>Mon, 27 May 2024 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36105</strong></p>
  <p>dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Prior to versions 1.6.15, 1.7.15, and 1.8.1, Binding to `INADDR_ANY (0.0.0.0)` or `IN6ADDR_ANY (::)` exposes an application on all network interfaces, increasing the risk of unauthorized access. As stated in the Python docs, a special form for address is acce…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36105">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
