<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:59:03.026742+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292443</id>
    <title>EUVD-2026-292443</title>
    <updated>2026-10-05T15:59:03.086007+00:00</updated>
    <content>EUVD-2026-292443</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292443"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40931</id>
    <title>fkie_cve-2026-40931</title>
    <updated>2026-10-05T15:59:03.086054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. This check verifies if a resolved path string starts with the destination directory string but fails to account for the actual filesystem state. By exploiting this "Logical vs. Physical" divergence, an attacker can bypass the security check using a Directory Poisoning technique (pre-existing symbolic links). This vulnerability is fixed in 2.1.1 and 1.10.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40931"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4c3q-x735-j3r5</id>
    <title>GHSA-4c3q-x735-j3r5 — Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing</title>
    <updated>2026-10-05T15:59:03.086110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: compressing</p>
<p>**1. Executive Summary**
This report documents a critical security research finding in the `compressing` npm package (specifically tested on the latest **v2.1.0**). The core vulnerability is a **Partial Fix Bypass** of **CVE-2026-24884**.</p>
<p>The current patch relies on a purely logical string validation within the `isPathWithinParent` utility. This check verifies if a resolved path string starts with the destination directory string but fails to account for the **actual filesystem state**. By exploiting this "Logical vs. Physical" divergence, we successfully bypassed the security check using a Directory Poisoning technique (pre-existing symbolic links).</p>
<p>**Key Findings:**</p>
<p>* **Vulnerable Component:** `lib/utils.js` -&gt; `isPathWithinParent()`
* **Flaw Type:** Incomplete validation (lack of recursive `lstat` checks).
* **Primary Attack Vector:** **Supply Chain via Git Clone** The attack requires zero victim interaction beyond standard developer workflow (`git clone` + `node app.js`). Git natively preserves symlinks during clone, automatically deploying the malicious symlink to victim's machine without any additional attacker access.
* **Result:** Successfully achieved arbitrary file writes outside the intended extraction root on the latest library version.</p>
<p>**2. Deep-Dive: Technical Root Cause Analysis**
The vulnerability exists because of a fundamental disconnect between how the library **validates** a path and how the Operating System **executes** a write to that path.</p>
<p>* **1.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4c3q-x735-j3r5"/>
  </entry>
</feed>
