<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:11:22.324537+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275062</id>
    <title>EUVD-2026-275062</title>
    <updated>2026-10-03T06:11:22.424685+00:00</updated>
    <content>EUVD-2026-275062</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29065</id>
    <title>fkie_cve-2026-29065</title>
    <updated>2026-10-03T06:11:22.424723+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives. This issue has been patched in version 0.54.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-29065"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-25g8-2mcf-fcx9</id>
    <title>GHSA-25g8-2mcf-fcx9 — changedetection.io has Zip Slip vulnerability in the backup restore functionality</title>
    <updated>2026-10-03T06:11:22.424762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: changedetection.io</p>
<p>### Summary
A Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives.</p>
<p>### Details</p>
<p>A Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives. The application uses zipfile.extractall() without validating entry paths, allowing ../ sequences to escape the extraction directory.</p>
<p>Vulnerable Code (lines 50-53):
```
def restore_backup(self, filename):
    with zipfile.ZipFile(filename, 'r') as zip_ref:
        # VULNERABLE: No path validation before extraction
        zip_ref.extractall(self.datastore_path)
```
The extractall() function preserves the relative paths stored within the ZIP archive. When a malicious ZIP contains entries with ../ path traversal sequences, these files are extracted outside the intended directory.</p>
<p>| Path in ZIP | Target File | Impact |
| --- | --- | --- |
| ../secret.txt | Flask secret key | Session forgery, auth bypass |
| ../changedetection.json | App settings | Disable password, inject backdoor |
| ../url-watches.json | Watch index | Inject malicious watches |
| ../{uuid}/watch.json | Watch config | Modify any watch |</p>
<p>Attacker uploads ZIP via the backup restore functionality at /backups/restore
Application extracts files without validation, writing attacker content to sensitive locations</p>
<p>### PoC</p>
<p>Step 1: Create Malicious ZIP
```
import zipfile
import json</p>
<p>with zipfile.ZipFile("zipslip.zip",…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-25g8-2mcf-fcx9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2129</id>
    <title>PYSEC-2026-2129</title>
    <updated>2026-10-03T06:11:22.424817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: changedetection-io</p>
<p>changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives. This issue has been patched in version 0.54.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2129"/>
  </entry>
</feed>
