<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T20:34:24.094584+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-267665</id>
    <title>EUVD-2026-267665</title>
    <updated>2026-10-07T20:34:24.139584+00:00</updated>
    <content>EUVD-2026-267665</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-267665"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25760</id>
    <title>fkie_cve-2026-25760</title>
    <updated>2026-10-07T20:34:24.139620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated path traversal / arbitrary file read issue, and it can expose credentials, configs, and keys. This vulnerability is fixed in 1.6.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25760"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2286-hxv5-cmp2</id>
    <title>GHSA-2286-hxv5-cmp2 — Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated)</title>
    <updated>2026-10-07T20:34:24.139652+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/bishopfox/sliver</p>
<p>## Summary
A Path Traversal vulnerability in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated **Path Traversal / arbitrary file read** issue, and it can expose credentials, configs, and keys.</p>
<p>## Affected Component
- Website content management (gRPC): `WebsiteAddContent`, `Website`, `Websites`
- Server-side file read in `Website.ToProtobuf`</p>
<p>## Impact
- **Arbitrary file read** as the Sliver server OS user.
- Exposure of sensitive data such as operator configs, TLS keys, tokens, and logs.</p>
<p>## Root Cause
The server accepts and persists arbitrary website paths from the operator, then later reads from disk using that path without sanitization or containment.</p>
<p>## Vulnerable Code References
- `server/rpc/rpc-website.go:100` — accepts `content.Path` from operator RPC and persists it via `website.AddContent`
- `server/db/models/website.go:52` — reads from disk with `filepath.Join(webContentDir, webcontent.Path)` without validating or constraining `webcontent.Path`</p>
<p>## Proof of Concept (PoC)</p>
<p>### Steps (local test)
1. Build the server:
   ```bash
   go build -mod=vendor -tags go_sqlite,server -o sliver-server ./server
   ```
2. Create an operator config (permission `all` for website operations):
   ```bash
   ./sliver-server operator -n testop -l 127.0.0.1 -p 31337 -P all -o file -s /tmp
   ```
3. Start the daemon:
   ```bash
   ./sliver-server daemon -l 127.0.0.1 -p 31337
   ```
4. Run the PoC:
   `…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2286-hxv5-cmp2"/>
  </entry>
</feed>
