<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T08:03:34.210110+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-249479</id>
    <title>EUVD-2026-249479</title>
    <updated>2026-10-08T08:03:34.212814+00:00</updated>
    <content>EUVD-2026-249479</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-249479"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55013</id>
    <title>fkie_cve-2025-55013</title>
    <updated>2026-10-08T08:03:34.212846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Assemblyline 4 Service Client interfaces with the API to fetch tasks and publish the result for a service in Assemblyline 4. In versions below 4.6.1.dev138, the Assemblyline 4 Service Client (task_handler.py) accepts a SHA-256 value returned by the service server and uses it directly as a local file name.A malicious or compromised server (or any MITM that can speak to client) can return a path-traversal payload such as `../../../etc/cron.d/evil` and force the client to write the downloaded bytes to an arbitrary location on disk. This is fixed in version 4.6.1.dev138.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-55013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-75jv-vfxf-3865</id>
    <title>GHSA-75jv-vfxf-3865 — Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code</title>
    <updated>2026-10-08T08:03:34.212879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: assemblyline-service-client</p>
<p>**Path-Traversal -&gt; Arbitrary File Write in Assemblyline Service Client**</p>
<p>**IMPORTANT**: This vulnerability is valid if you decide to use the assemblyline-service-client outside of the normal practice to using Assemblyline in a production environment. In practice, this code should always be executed within a containerized environment such as [assemblyline-v4-service](https://github.com/CybercentreCanada/assemblyline-v4-service) which ensures filesystem-level permissions of what the running user is allowed to access. Furthermore, there is fewer chances for a MiTM compromise when deployed properly in a Docker or Kubernetes deployment where the platform will assign the correct network policies to secure connections between containers instead of relying on the user to set this up manually.</p>
<p>See https://github.com/CybercentreCanada/assemblyline/issues/382 for further discussion.</p>
<p>---</p>
<p>## 1. Summary  
The Assemblyline 4 **service client** (`task_handler.py`) accepts a SHA-256 value returned by the service **server** and uses it directly as a local file name.  
&gt; No validation / sanitisation is performed.</p>
<p>A **malicious or compromised server** (or any MITM that can speak to client) can return a path-traversal payload such as  
`../../../etc/cron.d/evil`  
and force the client to write the downloaded bytes to an arbitrary location on disk.</p>
<p>---</p>
<p>## 2. Affected Versions  
| Item | Value |
|---|---|
| **Component** | `assemblyline-service-client` |
| **Repository** | [CybercentreCana…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-75jv-vfxf-3865"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1194</id>
    <title>PYSEC-2026-1194 — Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code</title>
    <updated>2026-10-08T08:03:34.212933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: assemblyline-service-client</p>
<p>**Path-Traversal -&gt; Arbitrary File Write in Assemblyline Service Client**</p>
<p>**IMPORTANT**: This vulnerability is valid if you decide to use the assemblyline-service-client outside of the normal practice to using Assemblyline in a production environment. In practice, this code should always be executed within a containerized environment such as [assemblyline-v4-service](https://github.com/CybercentreCanada/assemblyline-v4-service) which ensures filesystem-level permissions of what the running user is allowed to access. Furthermore, there is fewer chances for a MiTM compromise when deployed properly in a Docker or Kubernetes deployment where the platform will assign the correct network policies to secure connections between containers instead of relying on the user to set this up manually.</p>
<p>See https://github.com/CybercentreCanada/assemblyline/issues/382 for further discussion.</p>
<p>---</p>
<p>## 1. Summary  
The Assemblyline 4 **service client** (`task_handler.py`) accepts a SHA-256 value returned by the service **server** and uses it directly as a local file name.  
&gt; No validation / sanitisation is performed.</p>
<p>A **malicious or compromised server** (or any MITM that can speak to client) can return a path-traversal payload such as  
`../../../etc/cron.d/evil`  
and force the client to write the downloaded bytes to an arbitrary location on disk.</p>
<p>---</p>
<p>## 2. Affected Versions  
| Item | Value |
|---|---|
| **Component** | `assemblyline-service-client` |
| **Repository** | [CybercentreCana…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1194"/>
  </entry>
</feed>
