<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T03:18:21.435850+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278452</id>
    <title>EUVD-2026-278452</title>
    <updated>2026-10-07T03:18:21.484406+00:00</updated>
    <content>EUVD-2026-278452</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278452"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34227</id>
    <title>fkie_cve-2026-34227</title>
    <updated>2026-10-07T03:18:21.484444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or destroying the entire compromised infrastructure, entirely through the operator's own browser. This issue has been patched in version 1.7.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34227"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6fpf-248c-m7wm</id>
    <title>GHSA-6fpf-248c-m7wm — Sliver One-Click Remote Access: Insecure CORS &amp; Unauthenticated MCP Interface</title>
    <updated>2026-10-07T03:18:21.484478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/bishopfox/sliver</p>
<p>A single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, `ntds.dit`) or destroying the entire compromised infrastructure, entirely through the operator's own browser.</p>
<p>## Description
The Sliver MCP server runs inside the Sliver Client and binds an unauthenticated HTTP and SSE interface to `localhost:8080` by default. The service returns a permissive `Access-Control-Allow-Origin: *` header on all responses.</p>
<p>Because this server is client-side, the attack surface is distributed across every individual operator in the operation. Any arbitrary website can issue cross-origin requests and interact with the MCP interface via an operator's browser, no credentials required.</p>
<p>If the interface is misconfigured to bind to all interfaces (`0.0.0.0`), the vulnerability escalates from a client-side CSRF/CORS issue to direct, unauthenticated remote access from any actor on the network.</p>
<p>## Exposed Methods
Exploitation grants unauthorized access to the following MCP tools:
- `list_sessions_and_beacons`
- `fs_ls`, `fs_pwd`, `fs_cd`
- `fs_cat`
- `fs_rm`, `fs_mv`, `fs_cp`, `fs_mkdir`
- `fs_chmod`, `fs_chown`</p>
<p>## PoC 
1. Start the Sliver client with MCP enabled (default `localhost:8080`)
2. Open a browser and load a page containing the [Proof of Concept JavaScript](https://github.com/skoveit/CVE-2026-34227).
3. Observe that the page successfully lists s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6fpf-248c-m7wm"/>
  </entry>
</feed>
