<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T05:56:06.477447+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330063</id>
    <title>EUVD-2026-330063</title>
    <updated>2026-10-06T05:56:06.526970+00:00</updated>
    <content>EUVD-2026-330063</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49402</id>
    <title>fkie_cve-2026-49402</title>
    <updated>2026-10-06T05:56:06.527030+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed shell: true to spawn / spawnSync / exec and friends. On Windows, the helper failed to quote arguments that contained cmd.exe metacharacters and did not neutralize % (which cmd.exe expands even inside double-quoted strings). An attacker who controlled any portion of an argument passed to such a call could inject arbitrary additional commands into the spawned cmd.exe invocation. This vulnerability is fixed in 2.7.10.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-49402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7xh3-mhg9-jcw8</id>
    <title>GHSA-7xh3-mhg9-jcw8 — Deno: Command Injection via spawnSync &amp; spawn on Windows</title>
    <updated>2026-10-06T05:56:06.527084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: deno</p>
<p>## Summary</p>
<p>Deno's `node:child_process` implementation provided an `escapeShellArg()` helper used when callers passed `shell: true` to `spawn` / `spawnSync` / `exec` and friends. On Windows, the helper failed to quote arguments that contained `cmd.exe` metacharacters such as `&amp;`, `|`, `&lt;`, `&gt;`, `^`, `!`, `(`, `)`, and did not neutralize `%` (which `cmd.exe` expands even inside double-quoted strings). An attacker who controlled any portion of an argument passed to such a call could inject arbitrary additional commands into the spawned `cmd.exe` invocation.</p>
<p>This was the Windows counterpart to CVE-2026-27190, which fixed the same class of bug in the Unix branch of `escapeShellArg`.</p>
<p>## Details</p>
<p>On Windows, `child_process` with `shell: true` ran the command via `cmd.exe /d /s /c "&lt;command line&gt;"`. Deno assembled that command line by joining the program name and each argument through `escapeShellArg()`.</p>
<p>The vulnerable check was:</p>
<p>```ts
// If no special characters, return as-is
if (!/[\s"\\]/.test(arg)) {
  return arg;
}
```</p>
<p>The regex covered only whitespace, double-quote, and backslash. Any argument containing `cmd.exe`-significant characters but none of those three was returned unquoted and therefore interpreted by the shell. The most straightforward exploit chained commands with `&amp;`:</p>
<p>```js
import { spawnSync } from "node:child_process";</p>
<p>spawnSync("echo", ["test&amp;calc.exe"], { shell: true, encoding: "utf-8" });
```</p>
<p>The reporter confirmed this launched `calc.exe` on Windows…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7xh3-mhg9-jcw8"/>
  </entry>
</feed>
