<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T18:05:54.168920+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-280035</id>
    <title>EUVD-2026-280035</title>
    <updated>2026-10-07T18:05:54.214904+00:00</updated>
    <content>EUVD-2026-280035</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-280035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35038</id>
    <title>fkie_cve-2026-35038</title>
    <updated>2026-10-07T18:05:54.214940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated user to bypass prototype boundary filtering to extract internal functions and properties from the global prototype object this violates data isolation and lets a user read more than they should. This issue has been patched in version 2.24.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qh3j-mrg8-f234</id>
    <title>GHSA-qh3j-mrg8-f234 — Signal K Server: Arbitrary Prototype Read via `from` Field Bypass</title>
    <updated>2026-10-07T18:05:54.214975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: signalk-server</p>
<p>## Summary</p>
<p>The /signalk/v1/applicationData/... JSON-patch endpoint allows users to modify stored application data. To prevent Prototype Pollution, the developers implemented an isPrototypePollutionPath guard. However, this guard only checks the path property of incoming JSON-patch objects. It completely fails to check the from property. Because JSON-patch operations like copy and move extract data using the from property path, an attacker can construct a payload where from targets /__proto__/someProperty, completely evading the security check and successfully executing an Arbitrary Prototype Read.</p>
<p>While this does not allow arbitrary code execution (as the destination path remains protected from __proto__), it does allow a user to exfiltrate internal Node functions and prototype state into their own application data.</p>
<p>## Vulnerability Root Cause</p>
<p>File: src/interfaces/applicationData.js (Lines 48-57)
```
const DANGEROUS_PATH_SEGMENTS = ['__proto__', 'constructor', 'prototype']</p>
<p>function isPrototypePollutionPath(pathString) {
  const segments = pathString.split(/[./]/)
  return segments.some((seg) =&gt; DANGEROUS_PATH_SEGMENTS.includes(seg))
}</p>
<p>function hasPrototypePollutionPatch(patches) {
  return patches.some(
    // [!VULNERABLE] Only checks patch.path, completely ignores patch.from
    (patch) =&gt; patch.path &amp;&amp; isPrototypePollutionPath(patch.path) 
  )
}
```
At Line 201:
```
if (hasPrototypePollutionPatch(req.body)) {
  res.status(400).send('invalid patch path')
  return
}…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qh3j-mrg8-f234"/>
  </entry>
</feed>
