<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:58:44.454457+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261426</id>
    <title>EUVD-2026-261426</title>
    <updated>2026-10-06T16:58:44.499130+00:00</updated>
    <content>EUVD-2026-261426</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261426"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65025</id>
    <title>fkie_cve-2025-65025</title>
    <updated>2026-10-06T16:58:44.499170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path traversal during NPM package tarball extraction. An attacker can craft a malicious NPM package containing specially crafted file paths (e.g., package/../../tmp/evil.js). When esm.sh downloads and extracts this package, files may be written to arbitrary locations on the server, escaping the intended extraction directory. This issue has been patched in version 136.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-65025"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h3mw-4f23-gwpw</id>
    <title>GHSA-h3mw-4f23-gwpw — esm.sh CDN service has arbitrary file write via tarslip</title>
    <updated>2026-10-06T16:58:44.499204+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/esm-dev/esm.sh</p>
<p>### Summary
The esm.sh CDN service is vulnerable to a Path Traversal (CWE-22) vulnerability during NPM package tarball extraction.  
An attacker can craft a malicious NPM package containing specially crafted file paths (e.g., `package/../../tmp/evil.js`).  
When esm.sh downloads and extracts this package, files may be written to arbitrary locations on the server, escaping the intended extraction directory.</p>
<p>Uploading files containing `../` in the path is not allowed on official registries (npm, GitHub), but the `X-Npmrc` header allows specifying any arbitrary registry.  
By setting the registry to an attacker-controlled server via the `X-Npmrc` header, this vulnerability can be triggered.</p>
<p>### Details
**file:** `server/npmrc.go`  
**line:** 552-567</p>
<p>```go
func extractPackageTarball(installDir string, pkgName string, tarball io.Reader) (err error) {
    
    pkgDir := path.Join(installDir, "node_modules", pkgName)
    
    tr := tar.NewReader(unziped)
    for {
        h, err := tr.Next()
        // ...
        
        // Strip tarball root directory
        _, name := utils.SplitByFirstByte(h.Name, '/')  // "package/../../tmp/evil" → "../../tmp/evil"
        filename := path.Join(pkgDir, name)             // ← No validation
        
        if h.Typeflag != tar.TypeReg {
            continue 
        }
        
        // Extension filtering
        extname := path.Ext(filename)
        if !(extname != "" &amp;&amp; (allowed_extensions)) {
            continue  // Only extract .js,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h3mw-4f23-gwpw"/>
  </entry>
</feed>
