<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T12:17:10.200746+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326618</id>
    <title>EUVD-2026-326618</title>
    <updated>2026-10-07T12:17:10.203055+00:00</updated>
    <content>EUVD-2026-326618</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50568</id>
    <title>fkie_cve-2026-50568</title>
    <updated>2026-10-07T12:17:10.203090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFilePath in pkg/utils/utils.go validated that a path stayed under a safe directory by calling strings.HasPrefix(path, safedir). This is a lexical check, not a directory boundary check: /packages-extra/evil starts with /packages, so it passed. The function did not enforce a path-separator boundary, so any sibling directory whose name began with the safe-directory string was accepted. Callers included the builder's Clean handler (pkg/builder/builder.go:208) and the fetcher's Fetch / Upload handlers (pkg/fetcher/fetcher.go). A tenant who could pre-create or control a sibling directory under the fetcher / builder's shared volume could induce a write or read outside the intended safe directory. This issue has been patched in version 1.25.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50568"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r5jh-q2mw-gcx4</id>
    <title>GHSA-r5jh-q2mw-gcx4 — Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape</title>
    <updated>2026-10-07T12:17:10.203129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/fission/fission</p>
<p>`SanitizeFilePath` in `pkg/utils/utils.go` validated that a path stayed under a safe directory by calling `strings.HasPrefix(path, safedir)`. This is a lexical check, not a directory boundary check: `/packages-extra/evil` starts with
`/packages`, so it passed. The function did not enforce a path-separator boundary, so any sibling directory whose name began with the safe-directory string was accepted.</p>
<p>Callers included the builder's `Clean` handler (`pkg/builder/builder.go:208`) and the fetcher's `Fetch` / `Upload` handlers (`pkg/fetcher/fetcher.go`). A tenant who could pre-create or control a sibling directory under the fetcher /
builder's shared volume could induce a write or read outside the intended safe directory.</p>
<p>### Affected</p>
<p>- Project: `github.com/fission/fission`
- Versions: all versions through v1.24.0 with `SanitizeFilePath` in the tree
- Audited commit: `647c141`
- Component: `pkg/utils/utils.go:SanitizeFilePath`
- Callers: `pkg/builder/builder.go:157,164,208`, `pkg/fetcher/fetcher.go:296,311,450,496,565,571`
- Configuration: default; requires a sibling directory to the safe dir to exist on the filesystem</p>
<p>Fix section (paste into the Fix / Patches field)</p>
<p>Fixed in [v1.25.0](https://github.com/fission/fission/releases/tag/v1.25.0) by:</p>
<p>- [PR #3445](https://github.com/fission/fission/pull/3445) (commit [`8298e33e`](https://github.com/fission/fission/commit/8298e33ea7457702f893eae11077987cf905edb4)) — migrate every `SanitizeFilePath` call site (fetcher: `storePath`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r5jh-q2mw-gcx4"/>
  </entry>
</feed>
