<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T08:35:23.027141+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265945</id>
    <title>EUVD-2026-265945</title>
    <updated>2026-10-06T08:35:23.030183+00:00</updated>
    <content>EUVD-2026-265945</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22864</id>
    <title>fkie_cve-2026-22864</title>
    <updated>2026-10-06T08:35:23.030219+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example .BAT, .Bat, etc.). This vulnerability is fixed in 2.5.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22864"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m3c4-prhw-mrx6</id>
    <title>GHSA-m3c4-prhw-mrx6 — Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass</title>
    <updated>2026-10-06T08:35:23.030260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: deno</p>
<p>### Summary
A prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched `.bat` or `.cmd`. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example `.BAT, .Bat`, etc.).</p>
<p>### POC
```javascript
const command = new Deno.Command('./test.BAT', {
  args: ['&amp;calc.exe'],
});
const child = command.spawn();
```
This causes `calc.exe` to be launched; see the attached screenshot for evidence.</p>
<p>**Patched in `CVE-2025-61787` — prevents execution of `.bat` and `.cmd` files:**
![photo_2025-10-10 02 27 23](https://github.com/user-attachments/assets/43df25e2-e2e1-48aa-8060-cb0a22637f1f)</p>
<p>**Bypass of the patched vulnerability:**
![photo_2025-10-10 02 27 25](https://github.com/user-attachments/assets/2be1afb4-84a1-4883-8e18-6a174fdd3615)</p>
<p>### Impact
The script launches calc.exe on Windows, demonstrating that passing user-controlled arguments to a spawned batch script can result in command-line injection.</p>
<p>### Mitigation</p>
<p>Users should update to Deno v2.5.6 or newer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m3c4-prhw-mrx6"/>
  </entry>
</feed>
