<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T08:26:03.269699+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-281107</id>
    <title>EUVD-2026-281107</title>
    <updated>2026-10-08T08:26:03.316290+00:00</updated>
    <content>EUVD-2026-281107</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-281107"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35412</id>
    <title>fkie_cve-2026-35412</title>
    <updated>2026-10-08T08:26:03.316338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated user with basic file upload permissions to overwrite arbitrary existing files by UUID. The TUS controller performs only collection-level authorization checks, verifying the user has some permission on directus_files, but never validates item-level access to the specific file being replaced. As a result, row-level permission rules (e.g., "users can only update their own files") are completely bypassed via the TUS path while being correctly enforced on the standard REST upload path. This vulnerability is fixed in 11.16.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35412"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qqmv-5p3g-px89</id>
    <title>GHSA-qqmv-5p3g-px89 — Directus: TUS Upload Authorization Bypass Allows Arbitrary File Overwrite</title>
    <updated>2026-10-08T08:26:03.316377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: directus</p>
<p>## Summary</p>
<p>Directus' TUS resumable upload endpoint (`/files/tus`) allows any authenticated user with basic file upload permissions to overwrite arbitrary existing files by UUID. The TUS controller performs only collection-level authorization checks, verifying the user has some permission on `directus_files`, but never validates item-level access to the specific file being replaced. As a result, row-level permission rules (e.g., "users can only update their own files") are completely bypassed via the TUS path while being correctly enforced on the standard REST upload path.</p>
<p>## Impact</p>
<p>- **Arbitrary file overwrite:** Any authenticated user with basic TUS upload permissions can overwrite any file in `directus_files` by UUID, regardless of row-level permission rules.
- **Permanent data loss:** The victim file's original stored bytes are deleted from storage and replaced with attacker-controlled content.
- **Metadata corruption:** The victim file's database record is updated with the attacker's filename, type, and size metadata.
Privilege escalation potential: If admin-owned files (e.g., application assets, templates) are stored in `directus_files`, a low-privilege user could replace them with malicious content.</p>
<p>## Workaround</p>
<p>Disable TUS uploads by setting `TUS_ENABLED=false` if resumable uploads are not required.</p>
<p>## Credit</p>
<p>This vulnerability was discovered and reported by [bugbunny.ai](https://bugbunny.ai).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qqmv-5p3g-px89"/>
  </entry>
</feed>
