<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T12:11:35.782105+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322483</id>
    <title>EUVD-2026-322483</title>
    <updated>2026-10-05T12:11:35.827443+00:00</updated>
    <content>EUVD-2026-322483</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44594</id>
    <title>fkie_cve-2026-44594</title>
    <updated>2026-10-05T12:11:35.827484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in package.json. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rg65-45m7-hq57</id>
    <title>GHSA-rg65-45m7-hq57 — esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files</title>
    <updated>2026-10-05T12:11:35.827521+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/esm-dev/esm.sh</p>
<p>### Summary</p>
<p>A Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the `browser` field in `package.json`. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.</p>
<p>### Details</p>
<p>The vulnerable code is in the `OnResolve` callback of the esbuild plugin:</p>
<p>https://github.com/esm-dev/esm.sh/blob/main/server/build.go</p>
<p>The plugin validates that resolved file paths stay within the package working directory. However, after this check, the `browser` field from `package.json` remaps the module path to an attacker-controlled value containing `../` sequences. No validation is performed after the remapping.</p>
<p>```go
// Sandbox check passes for the original "./d1.txt" path
if !strings.HasPrefix(filename, ctx.wd+string(os.PathSeparator)) {
    return esbuild.OnResolveResult{}, fmt.Errorf("could not resolve module %s", specifier)
}</p>
<p>// ... later, browser field remaps to attacker-controlled path:
if len(pkgJson.Browser) &gt; 0 &amp;&amp; ctx.isBrowserTarget() {
	if path, ok := pkgJson.Browser[modulePath]; ok {
		if path == "" {
			return esbuild.OnResolveResult{
				Path:      args.Path,
				Namespace: "browser-exclude",
			}, nil
		}
		if !isRelPathSpecifier(path) {
			externalPath, sideEffects, err := ctx.resolveExternalModule(path, args.Kind, withTypeJSON, analyzeMode)
			if err != nil {
				return esbuild.OnResolveResult{}, err
			}
			return esbuild.OnResolveResult{
				Path:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rg65-45m7-hq57"/>
  </entry>
</feed>
