<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:07:34.924717+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04351</id>
    <title>bdu:2026-04351</title>
    <updated>2026-10-03T17:07:34.943850+00:00</updated>
    <content>bdu:2026-04351</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04351"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0627</id>
    <title>certfr-2026-avi-0627 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T17:07:34.943888+00:00</updated>
    <content>certfr-2026-avi-0627</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0627"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-273675</id>
    <title>EUVD-2026-273675</title>
    <updated>2026-10-03T17:07:34.943908+00:00</updated>
    <content>EUVD-2026-273675</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-273675"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27699</id>
    <title>fkie_cve-2026-27699</title>
    <updated>2026-10-03T17:07:34.943920+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5rq4-664w-9x2c</id>
    <title>GHSA-5rq4-664w-9x2c — Basic FTP has Path Traversal Vulnerability in its downloadToDir() method</title>
    <updated>2026-10-03T17:07:34.943950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: basic-ftp</p>
<p>The `basic-ftp` library contains a path traversal vulnerability in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory.</p>
<p>## Source-to-Sink Flow</p>
<p>```
1. SOURCE: FTP server sends LIST response
└─&gt; "-rw-r--r-- 1 user group 1024 Jan 20 12:00 ../../../etc/passwd"</p>
<p>2. PARSER: parseListUnix.ts:100 extracts filename
└─&gt; file.name = "../../../etc/passwd"</p>
<p>3. VALIDATION: parseListUnix.ts:101 checks
└─&gt; if (name === "." || name === "..") ❌ (only filters exact matches)
└─&gt; "../../../etc/passwd" !== "." &amp;&amp; !== ".." ✅ PASSES</p>
<p>4. SINK: Client.ts:707 uses filename directly
└─&gt; const localPath = join(localDirPath, file.name)
└─&gt; join("/safe/download", "../../../etc/passwd")
└─&gt; Result: "/safe/download/../../../etc/passwd" → resolves to "/etc/passwd"</p>
<p>5. FILE WRITE: Client.ts:512 opens file
└─&gt; fsOpen(localPath, "w") → writes to /etc/passwd (outside intended directory)
```</p>
<p>## Vulnerable Code</p>
<p>**File**: `src/Client.ts:707`</p>
<p>```typescript
protected async _downloadFromWorkingDir(localDirPath: string): Promise&lt;void&gt; {
await ensureLocalDirectory(localDirPath)
for (const file of await this.list()) {
const localPath = join(localDirPath, file.name) // ⚠️ VULNERABLE
// file.name comes from untrusted FTP server, no sanitization
await this.downloadTo(localPath, file.name)
}
}
```</p>
<p>**Root Cause**:
- Parser validation (`parseListUnix.ts:101`) only…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5rq4-664w-9x2c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11452-1</id>
    <title>openSUSE-SU-2026:11452-1 — agama-integration-tests-1785848065.5562c7c-4.1 on GA media</title>
    <updated>2026-10-03T17:07:34.944006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>agama-integration-tests-1785848065.5562c7c-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11452-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27699</id>
    <title>UBUNTU-CVE-2026-27699</title>
    <updated>2026-10-03T17:07:34.944028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-proxy-agents, Ubuntu:25.10: node-proxy-agents, Ubuntu:26.04:LTS: node-proxy-agents</p>
<p>The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</id>
    <title>WID-SEC-W-2026-3046 — IBM Concert: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:07:34.944053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046"/>
  </entry>
</feed>
