<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T13:08:59.278980+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-263815</id>
    <title>EUVD-2026-263815</title>
    <updated>2026-10-06T13:08:59.329281+00:00</updated>
    <content>EUVD-2026-263815</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-263815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68155</id>
    <title>fkie_cve-2025-68155</title>
    <updated>2026-10-06T13:08:59.329319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter. Version 0.5.8 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g239-q96q-x4qm</id>
    <title>GHSA-g239-q96q-x4qm — @vitejs/plugin-rsc has an Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint</title>
    <updated>2026-10-06T13:08:59.329355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @vitejs/plugin-rsc</p>
<p>## Summary</p>
<p>The `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows **unauthenticated arbitrary file read** during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter.</p>
<p>**Severity:** High
**Attack Vector:** Network  
**Privileges Required:** None  
**Scope:** Development mode only (`vite dev`)</p>
<p>---</p>
<p>## Impact</p>
<p>### Who Is Affected?</p>
<p>- **All developers** using `@vitejs/plugin-rsc` during development
- Projects running `vite dev` with the RSC plugin enabled</p>
<p>### Attack Scenarios</p>
<p>1. **Network-Exposed Dev Servers:**  
   When developers run `vite --host 0.0.0.0` (common for mobile testing), attackers on the same network can read files.</p>
<p>2. ~**XSS-Based Attacks:**~
   ~If the application has an XSS vulnerability, malicious JavaScript can fetch sensitive files and exfiltrate them.~</p>
<p>3. ~**Malicious Dependencies:** ~
   ~A compromised npm package could include code that reads files during development.~</p>
<p>4. ~**DNS Rebinding:**~ (EDIT: This doesn't apply since https://github.com/vitejs/vite/pull/20222)
   ~An attacker could use DNS rebinding to access the localhost dev server from a malicious website.~</p>
<p>### What Can Be Leaked?</p>
<p>- Environment files (`.env`, `.env.local`, `.env.production`)
- SSH keys (`~/.ssh/id_rsa`, `~/.ssh/id_ed25519`)
- Cloud credentials (`~/.aws/credentials`, `~/.config/gcloud/`)
- Database passwords and API keys
- Source code…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g239-q96q-x4qm"/>
  </entry>
</feed>
