<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T19:14:32.657506+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318153</id>
    <title>EUVD-2026-318153</title>
    <updated>2026-10-06T19:14:32.714551+00:00</updated>
    <content>EUVD-2026-318153</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41693</id>
    <title>fkie_cve-2026-41693</title>
    <updated>2026-10-06T19:14:32.714765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18next-fs-backend substitutes the lng and ns options directly into the configured loadPath / addPath templates and then read / write the resulting file from disk. The interpolation is unencoded and unvalidated, so a crafted lng or ns value — containing .., a path separator, a control character, a prototype key, or simply an unexpectedly long string — allows an attacker who can influence either value to read or overwrite files outside the intended locale directory. When lng / ns are derived from untrusted input (request-scoped i18next instances behind an HTTP layer such as i18next-http-middleware, or any framework that lets the end user pick the language via query string, cookie, or header), a single request such as ?lng=../../../../etc/passwd causes the backend to attempt to read that path. This issue has been patched in version 2.6.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8847-338w-5hcj</id>
    <title>GHSA-8847-338w-5hcj — i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite</title>
    <updated>2026-10-06T19:14:32.714945+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: i18next-fs-backend</p>
<p>### Summary</p>
<p>Versions of `i18next-fs-backend` prior to 2.6.4 interpolate the caller-supplied `lng` and `ns` values directly into the configured `loadPath` and `addPath` templates with no path-component validation and no sanitisation. When an application exposes the resolved language code to user-controlled input (`?lng=` query parameter, cookie, request header), a crafted value can break out of the intended locale directory.</p>
<p>Affected call sites in `lib/index.js`:</p>
<p>- `read` (line 38 pre-patch): `const filename = interpolate(loadPath, { lng: language, ns: namespace })`
- `removeFile` (line 101 pre-patch): same pattern against `addPath`
- `writeFile` (line 127 pre-patch): same pattern against `addPath` for queued missing-key writes</p>
<p>The helper `interpolate` in `lib/utils.js` substitutes raw values with no encoding — unlike the `addQueryString` helper in `i18next-http-backend`, there is no equivalent safety for path interpolation.</p>
<p>### Impact</p>
<p>- **Arbitrary file read.** With a `loadPath` like `/locales/{{lng}}/{{ns}}.json`, an attacker-controlled `lng = '../../etc'` (and matching `ns`) causes the backend to read a file outside the locale directory. For parsers that tolerate arbitrary content (YAML's freeform text), the file contents surface as a translation resource.
- **Arbitrary file overwrite.** `addPath` is interpolated the same way for missing-key writes (the `create()` code path and the debounced writer in `writeFile`). A traversing `lng`/`ns` combination can cause the pr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8847-338w-5hcj"/>
  </entry>
</feed>
