CVE-2026-78136: High severity chirpmyradio CHIRP vulnerability
Published Aug 23, 2026
·Updated
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in cleantmode in drivers/kenwooditm.py.
Affected Software
1 affected component
chirpmyradio CHIRP<39178db
Event History
Aug 23, 2026
CVE Published
via MITRE·12:48 AM
Data Sourced
via MITRE·12:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to exploit this issue?
The attacker must persuade a user to process a crafted CSV file with CHIRP. Exploitation requires user interaction, but no privileges are required beforehand.
2
Which CHIRP versions are affected?
CHIRP versions before commit 39178db are affected. The issue is fixed by commit 39178dbfc4fece083ab9ed20286d6ae3a91a718e.
3
What can happen if exploitation succeeds?
Successful exploitation can result in code execution with the confidentiality, integrity, and availability impact of the user running CHIRP.