<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:05:56.432965+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-196424</id>
    <title>EUVD-2026-196424</title>
    <updated>2026-10-03T20:05:56.435660+00:00</updated>
    <content>EUVD-2026-196424</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-196424"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-37897</id>
    <title>fkie_cve-2023-37897</title>
    <updated>2026-10-03T20:05:56.435704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1` introduces bypass of the denylist due to incorrect return value from `isDangerousFunction()`, which allows to execute the payload prepending double backslash (`\\`). The `isDangerousFunction()` check in version 1.7.42 and onwards retuns `false` value instead of `true` when the `\` symbol is found in the `$name`. This vulnerability can be exploited if the attacker has access to: 1. an Administrator account, or 2. a non-administrator, user account that has Admin panel access and Create/Update page permissions. A fix for this vulnerability has been introduced in commit `b4c6210` and is included in release version `1.7.42.2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-37897"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9436-3gmp-4f53</id>
    <title>GHSA-9436-3gmp-4f53 — grav Server-side Template Injection (SSTI) mitigation bypass</title>
    <updated>2026-10-03T20:05:56.435752+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getgrav/grav</p>
<p>### Summary
The fix for SSTI using `|map`, `|filter` and `|reduce` twigs implemented in the commit [71bbed1](https://github.com/getgrav/grav/commit/71bbed12f950de8335006d7f91112263d8504f1b) introduces bypass of the denylist due to incorrect return value from `isDangerousFunction()`, which allows to execute the payload prepending double backslash (`\\`)</p>
<p>### Details
The `isDangerousFunction()` check in version 1.7.42 and onwards retuns `false` value instead of `true` when the `\` symbol is found in the `$name`.</p>
<p>```php
...
        if (strpos($name, "\\") !== false) {
            return false;
        }</p>
<p>if (in_array($name, $commandExecutionFunctions)) {
            return true;
        }
...
```
Based on the code where the function is used, it is expected that any dangerous condition would return `true`
```php
    /**
     * @param Environment $env
     * @param array $array
     * @param callable|string $arrow
     * @return array|CallbackFilterIterator
     * @throws RuntimeError
     */
    function mapFunc(Environment $env, $array, $arrow)
    {
        if (!$arrow instanceof \Closure &amp;&amp; !is_string($arrow) || Utils::isDangerousFunction($arrow)) {
            throw new RuntimeError('Twig |map("' . $arrow . '") is not allowed.');
	}
```
when `|map('\system')` is used in the malicious payload, the single backslash is dropped prior to reaching `strpos($name, '\\')` check, thus `$name` variable already has no backslash, and the command is blacklisted because it reache…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9436-3gmp-4f53"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-37897</id>
    <title>gsd-2023-37897</title>
    <updated>2026-10-03T20:05:56.435829+00:00</updated>
    <content>gsd-2023-37897</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-37897"/>
  </entry>
</feed>
