<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:49:13.505811+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-325535</id>
    <title>EUVD-2026-325535</title>
    <updated>2026-10-06T17:49:13.559000+00:00</updated>
    <content>EUVD-2026-325535</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-325535"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46393</id>
    <title>fkie_cve-2026-46393</title>
    <updated>2026-10-06T17:49:13.559037+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 26.0.0 allows authenticated users to fetch arbitrary internal or local resources and write the responses to a web-accessible directory, enabling arbitrary file read and internal network access. Version 26.0.0 contains a fix.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q862-gcgq-5m6g</id>
    <title>GHSA-q862-gcgq-5m6g — HAXcms createSite SSRF Enables Arbitrary File Read</title>
    <updated>2026-10-06T17:49:13.559070+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @haxtheweb/haxcms-nodejs</p>
<p>### Summary  
An authenticated Server-Side Request Forgery (SSRF) vulnerability in HAXcms allows users to fetch arbitrary internal or local resources and write the responses to a web-accessible directory, enabling arbitrary file read and internal network access.</p>
<p>### Details  
The `createSite` endpoint in HAXcms (v11.0.6) accepts a `build.files` parameter that allows an authenticated user to supply arbitrary URLs or local file paths. This input is processed without validation and ultimately fetched server-side using `file_get_contents()`.</p>
<p>The data flow is as follows:
- User input (`build.files`) is processed via `object_to_array()` into a PHP array  
- Assigned to `$filesToDownload` in `Operations.php` (line 2626)  
- Iterated over in `Operations.php` (line 2730), where each entry is passed to `HAXCMSFile::save()` with bulk-import enabled</p>
<p>In `HAXCMSFile.php` (line 30), the following occurs:
```php
file_get_contents($upload['tmp_name']);
```</p>
<p>Here, tmp_name is attacker-controlled and may contain:</p>
<p>- External URLs (`http://attacker.com`)
- Internal services (`http://127.0.0.1`)
- Cloud metadata endpoints (`http://169.254.169.254`)
- Local file paths (`/etc/passwd`, `/proc/self/environ`)</p>
<p>The bulk-import flag bypasses `is_uploaded_file()` validation, which normally ensures the file originates from a legitimate upload. The only restriction is an extension whitelist based on the filename (array key), which is fully attacker-controlled.</p>
<p>There are no restrictions on:</p>
<p>- URL sc…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q862-gcgq-5m6g"/>
  </entry>
</feed>
