CVE-2026-78136 affects chirpmyradio CHIRP before commit 39178db, allowing eval injection through crafted CSV data. The vulnerability exists in the _clean_tmode function within drivers/kenwood_itm.py. An attacker can exploit this by supplying malicious CSV data, potentially leading to arbitrary code execution. A proof-of-concept has been published on GitHub demonstrating code execution via a malicious image file. The fix is available in commit 39178dbfc4fece083ab9ed20286d6ae3a91a718e in the official CHIRP repository. CHIRP is an open-source tool used for programming amateur radios, making this vulnerability relevant to the ham radio community. Users should update to a version including the patch commit to mitigate the risk.