<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T02:01:06.878624+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-4741</id>
    <title>EUVD-2026-4741</title>
    <updated>2026-10-09T02:01:06.944715+00:00</updated>
    <content>EUVD-2026-4741</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-4741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-30265</id>
    <title>fkie_cve-2024-30265</title>
    <updated>2026-10-09T02:01:06.944769+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-30265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2q59-h24c-w6fg</id>
    <title>GHSA-2q59-h24c-w6fg — Voilà Local file inclusion</title>
    <updated>2026-10-09T02:01:06.944825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: voila</p>
<p>### Impact</p>
<p>Any deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server.</p>
<p>Whether this still requires authentication depends on how voilà is deployed.</p>
<p>### Patches</p>
<p>This is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+</p>
<p>### Workarounds</p>
<p>None.</p>
<p>### References</p>
<p>CWE-73: External Control of File Name or Path</p>
<p>### Original report</p>
<p>I have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila).</p>
<p>The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:</p>
<p>```
$ curl localhost:8866/static/etc/passwd
```</p>
<p>...or by using a webbrowser to download the file.</p>
<p>I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
`"static_path"` gets set to `"/"`, irrespective of the actual `"--static"` cli option. Because of that, the `tornado.web.StaticFileHandler` gets initialized with `path="/"`. Then, `tornado.web.StaticFileHandler.get` calls `tornado.web.StaticFileHandler.get_absolute_path` with `root="/"` and `path="[USER SUPPLIED PATH]"`, which leads to local file inclusion. An attacker can request any file on the system they want (that the user running voila has access to).</p>
<p>I suspect this was an…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2q59-h24c-w6fg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-30265</id>
    <title>gsd-2024-30265</title>
    <updated>2026-10-09T02:01:06.944926+00:00</updated>
    <content>gsd-2024-30265</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-30265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2027</id>
    <title>PYSEC-2026-2027 — Voilà Local file inclusion</title>
    <updated>2026-10-09T02:01:06.944950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: voila</p>
<p>### Impact</p>
<p>Any deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server.</p>
<p>Whether this still requires authentication depends on how voilà is deployed.</p>
<p>### Patches</p>
<p>This is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+</p>
<p>### Workarounds</p>
<p>None.</p>
<p>### References</p>
<p>CWE-73: External Control of File Name or Path</p>
<p>### Original report</p>
<p>I have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila).</p>
<p>The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:</p>
<p>```
$ curl localhost:8866/static/etc/passwd
```</p>
<p>...or by using a webbrowser to download the file.</p>
<p>I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
`"static_path"` gets set to `"/"`, irrespective of the actual `"--static"` cli option. Because of that, the `tornado.web.StaticFileHandler` gets initialized with `path="/"`. Then, `tornado.web.StaticFileHandler.get` calls `tornado.web.StaticFileHandler.get_absolute_path` with `root="/"` and `path="[USER SUPPLIED PATH]"`, which leads to local file inclusion. An attacker can request any file on the system they want (that the user running voila has access to).</p>
<p>I suspect this was an…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2027"/>
  </entry>
</feed>
