<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T22:46:53.071211+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-267393</id>
    <title>EUVD-2026-267393</title>
    <updated>2026-10-07T22:46:53.125079+00:00</updated>
    <content>EUVD-2026-267393</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-267393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25228</id>
    <title>fkie_cve-2026-25228</title>
    <updated>2026-10-07T22:46:53.125124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to read, write, and list arbitrary files and directories on the filesystem. The validateAppId() function blocks forward slashes (/) but not backslashes (\), which are treated as directory separators by path.join() on Windows. This enables attackers to escape the intended applicationData directory. This vulnerability is fixed in 2.20.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25228"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vrhw-v2hw-jffx</id>
    <title>GHSA-vrhw-v2hw-jffx — SignalK Server has Path Traversal leading to information disclosure</title>
    <updated>2026-10-07T22:46:53.125164+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: signalk-server</p>
<p>### Summary
A Path Traversal vulnerability in SignalK Server's `applicationData` API allows authenticated users on Windows systems to read, write, and list arbitrary files and directories on the filesystem. The `validateAppId()` function blocks forward slashes (`/`) but not backslashes (`\`), which are treated as directory separators by `path.join()` on Windows. This enables attackers to escape the intended `applicationData` directory.</p>
<p>### Details
**Platform**: Windows (Linux only allows traversal up a single directory)
**Authentication Required**: Yes (ability to write depends on user's permission)</p>
<p>The vulnerability exists in the `validateAppId()` function within the applicationData API handler. This function validates the `appid` parameter but only checks for forward slashes:</p>
<p>```javascript
// Simplified vulnerable code pattern
function validateAppId(appid) {
  if (appid.includes('/') || appid.length &gt;= 30) {
    return false;
  }
  return true;
}</p>
<p>// Later used in path construction
const dataPath = path.join(configPath, 'applicationData', 'users', deviceId, appid);
```</p>
<p>**Root Cause:**
- The validation only blocks `/` characters
- On Windows, `path.join()` uses the platform's native path separator
- Windows treats both `/` and `\` as valid directory separators
- Backslash-based traversal sequences like `..\..\..` pass validation
- When `path.join()` processes these on Windows, each `..` traverses up one directory level</p>
<p>### PoC
```python
#!/usr/bin/env python3</p>
<p>import a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vrhw-v2hw-jffx"/>
  </entry>
</feed>
