<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:19:29.580296+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-358368</id>
    <title>EUVD-2026-358368</title>
    <updated>2026-10-06T18:19:29.645171+00:00</updated>
    <content>EUVD-2026-358368</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-358368"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53541</id>
    <title>fkie_cve-2026-53541</title>
    <updated>2026-10-06T18:19:29.645214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action's configuration. However, prior to commit ebffd9f040f791208aee1db2e5a8aecd1e3e603d, a special case allows any argument whose name starts with `ot_` to bypass this filter. While two system arguments (`ot_executionTrackingId` and `ot_username`) are injected by OliveTin and overridden, all other `ot_`-prefixed arguments supplied by the user pass through unmodified. These bypassed arguments are not type-checked — the validation loop only iterates over the action's defined arguments, so `ot_`-prefixed arguments skip all type safety checks entirely; set as environment variables — via `buildEnv()`, with completely unvalidated values, and passed to the executed command; and included in the template context — available as `.Arguments.ot_*` in template rendering. Commit ebffd9f040f791208aee1db2e5a8aecd1e3e603d contains a patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-prj9-97mp-mwh2</id>
    <title>GHSA-prj9-97mp-mwh2 — OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering</title>
    <updated>2026-10-06T18:19:29.645260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/OliveTin/OliveTin</p>
<p>### Description</p>
<p>The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action's configuration. However, a special case allows any argument whose name starts with `ot_` to bypass this filter. While two system arguments (`ot_executionTrackingId` and `ot_username`) are injected by OliveTin and overridden, all other `ot_`-prefixed arguments supplied by the user pass through unmodified.</p>
<p>These bypassed arguments are:</p>
<p>1. **Not type-checked** — the validation loop only iterates over the action's defined arguments, so `ot_`-prefixed arguments skip all type safety checks entirely.
2. **Set as environment variables** — via `buildEnv()`, with completely unvalidated values, and passed to the executed command.
3. **Included in the template context** — available as `.Arguments.ot_*` in template rendering.</p>
<p>### Affected Code</p>
<p>**Filter bypass — `service/internal/executor/executor.go` (lines 728–731):**</p>
<p>```go
func keepArgument(name string, definedNames map[string]struct{}) bool {
    _, ok := definedNames[name]
    return ok || strings.HasPrefix(name, "ot_")
}
```</p>
<p>**System args only override two keys — `service/internal/executor/executor.go` (lines 742–745):**</p>
<p>```go
func injectSystemArgs(req *ExecutionRequest) {
    req.Arguments["ot_executionTrackingId"] = req.TrackingID
    req.Arguments["ot_username"] = req.AuthenticatedUser.Username
}
```</p>
<p>Any other `ot_`-prefixed argument (e.g., `ot_malicious`) survives both fu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-prj9-97mp-mwh2"/>
  </entry>
</feed>
