<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:12:35.420121+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-328536</id>
    <title>EUVD-2026-328536</title>
    <updated>2026-10-03T06:12:35.483717+00:00</updated>
    <content>EUVD-2026-328536</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-328536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48797</id>
    <title>fkie_cve-2026-48797</title>
    <updated>2026-10-03T06:12:35.483754+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push. The CLI accepts two operator-facing flags intended as security controls: --auth user:pass — documented as "require HTTP Basic authentication on every request to the UI." and--share — documented as "expose the UI on a public address; requires --auth." When --auth user:pass is passed, the CLI prints Auth: enabled (user: &lt;username&gt;) to confirm to the operator that authentication is active, then exports BACKPROPAGATE_UI_AUTH=user:pass to the subprocess that launches the Reflex backend. The Reflex backend (backpropagate/ui_app/**) never reads BACKPROPAGATE_UI_AUTH. No authentication middleware is registered. No request-level guard runs. No WebSocket upgrade guard runs. Any client that reaches the bound port — local or remote, depending on whether --share is used — has full UI access. An inline comment at backpropagate/cli.py:1217-1218 in the v1.1.0 source documents the gap: "For Phase 1 the variable is exported but Reflex doesn't read it yet." This comment was internal-facing; the user-facing documentation (README, CHANGELOG, SHIP_GATE) advertised the contract as enforced. An attacker who reaches the bound port can read uploaded datasets, trigger arbitrary training runs…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f65r-h4g3-3h9h</id>
    <title>GHSA-f65r-h4g3-3h9h — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication</title>
    <updated>2026-10-03T06:12:35.483812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: backpropagate, npm: @mcptoolshop/backpropagate</p>
<p>## Summary</p>
<p>In `backpropagate &gt;= 1.1.0`, the optional Reflex web UI (`pip install backpropagate[ui]`, launched via `backprop ui`) exposes a training control plane: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push.</p>
<p>The CLI accepts two operator-facing flags intended as security controls:</p>
<p>- `--auth user:pass` — documented as "require HTTP Basic authentication on every request to the UI."
- `--share` — documented as "expose the UI on a public address; requires `--auth`."</p>
<p>When `--auth user:pass` is passed, the CLI prints `Auth: enabled (user: &lt;username&gt;)` to confirm to the operator that authentication is active, then exports `BACKPROPAGATE_UI_AUTH=user:pass` to the subprocess that launches the Reflex backend.</p>
<p>**The Reflex backend (`backpropagate/ui_app/**`) never reads `BACKPROPAGATE_UI_AUTH`.** No authentication middleware is registered. No request-level guard runs. No WebSocket upgrade guard runs. Any client that reaches the bound port — local or remote, depending on whether `--share` is used — has full UI access.</p>
<p>An inline comment at `backpropagate/cli.py:1217-1218` in the v1.1.0 source documents the gap: *"For Phase 1 the variable is exported but Reflex doesn't read it yet."* This comment was internal-facing; the user-facing documentation (README, CHANGELOG, SHIP_GATE) advertised the contract as enforced.</p>
<p>This advisory is filed primarily because the runtime contradicted an operator-facing security claim. Cod…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f65r-h4g3-3h9h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-291</id>
    <title>PYSEC-2026-291 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication</title>
    <updated>2026-10-03T06:12:35.483879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: backpropagate</p>
<p>## Summary</p>
<p>In `backpropagate &gt;= 1.1.0`, the optional Reflex web UI (`pip install backpropagate[ui]`, launched via `backprop ui`) exposes a training control plane: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push.</p>
<p>The CLI accepts two operator-facing flags intended as security controls:</p>
<p>- `--auth user:pass` — documented as "require HTTP Basic authentication on every request to the UI."
- `--share` — documented as "expose the UI on a public address; requires `--auth`."</p>
<p>When `--auth user:pass` is passed, the CLI prints `Auth: enabled (user: &lt;username&gt;)` to confirm to the operator that authentication is active, then exports `BACKPROPAGATE_UI_AUTH=user:pass` to the subprocess that launches the Reflex backend.</p>
<p>**The Reflex backend (`backpropagate/ui_app/**`) never reads `BACKPROPAGATE_UI_AUTH`.** No authentication middleware is registered. No request-level guard runs. No WebSocket upgrade guard runs. Any client that reaches the bound port — local or remote, depending on whether `--share` is used — has full UI access.</p>
<p>An inline comment at `backpropagate/cli.py:1217-1218` in the v1.1.0 source documents the gap: *"For Phase 1 the variable is exported but Reflex doesn't read it yet."* This comment was internal-facing; the user-facing documentation (README, CHANGELOG, SHIP_GATE) advertised the contract as enforced.</p>
<p>This advisory is filed primarily because the runtime contradicted an operator-facing security claim. Cod…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-291"/>
  </entry>
</feed>
