<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:16:40.687120+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-183624</id>
    <title>EUVD-2026-183624</title>
    <updated>2026-10-02T23:16:40.690104+00:00</updated>
    <content>EUVD-2026-183624</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-183624"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-10541</id>
    <title>fkie_cve-2016-10541</title>
    <updated>2026-10-02T23:16:40.690148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape "&gt;" and "&lt;" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-10541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qg8p-v9q4-gh34</id>
    <title>GHSA-qg8p-v9q4-gh34 — Potential Command Injection in shell-quote</title>
    <updated>2026-10-02T23:16:40.690196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: shell-quote</p>
<p>Affected versions of `shell-quote` do not properly escape command line arguments, which may result in command injection if the library is used to escape user input destined for use as command line arguments.</p>
<p>## Proof of Concept:</p>
<p>The following characters are not escaped properly: `&gt;`,`;`,`{`,`}`</p>
<p>Bash has a neat but not well known feature known as "Bash Brace Expansion", wherein a sub-command can be executed without spaces by running it between a set of `{}` and using the `,` instead of ` ` to seperate arguments. Because of this, full command injection is possible even though it was initially thought to be impossible.</p>
<p>```
   const quote = require('shell-quote').quote;
   console.log(quote(['a;{echo,test,123,234}']));
   // Actual                    "a;{echo,test,123,234}"
   // Expected                  "a\;\{echo,test,123,234\}"
   // Functional Equivalent     "a; echo 'test' '123' '1234'"
```</p>
<p>## Recommendation</p>
<p>Update to version 1.6.1 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qg8p-v9q4-gh34"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-10541</id>
    <title>gsd-2016-10541</title>
    <updated>2026-10-02T23:16:40.690236+00:00</updated>
    <content>gsd-2016-10541</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-10541"/>
  </entry>
</feed>
