<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T07:35:55.130673+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338894</id>
    <title>EUVD-2026-338894</title>
    <updated>2026-10-06T07:35:55.221498+00:00</updated>
    <content>EUVD-2026-338894</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54910</id>
    <title>fkie_cve-2026-54910</title>
    <updated>2026-10-06T07:35:55.221540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors. The primary vector is the `path` parameter: it is passed directly to `idx.GetRealPath()` without calling `SanitizeUserPath()`, allowing an attacker to escape the storage root and set `parentDir` to any directory on the host. No existing anchor file is required.  The secondary vector is the `name` parameter: it is joined with `parentDir` via `filepath.Join(parentDir, name)` without stripping directory components, allowing traversal relative to any resolved `parentDir`. Any authenticated user (regardless of role or permissions) can exploit either vector to read any text file readable by the server process, including `/etc/passwd`, SSH keys, database credentials, and JWT signing keys. Version 1.4.3-beta patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vvp7-h4fj-m28w</id>
    <title>GHSA-vvp7-h4fj-m28w — FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files</title>
    <updated>2026-10-06T07:35:55.221604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gtsteffaniak/filebrowser/backend</p>
<p>### Summary</p>
<p>The `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors.</p>
<p>The primary vector is the `path` parameter: it is passed directly to `idx.GetRealPath()` without calling `SanitizeUserPath()`, allowing an attacker to escape the storage root and set `parentDir` to any directory on the host. No existing anchor file is required.</p>
<p>The secondary vector is the `name` parameter: it is joined with `parentDir` via `filepath.Join(parentDir, name)` without stripping directory components, allowing traversal relative to any resolved `parentDir`.</p>
<p>Any authenticated user (regardless of role or permissions) can exploit either vector to read any text file readable by the server process, including `/etc/passwd`, SSH keys, database credentials, and JWT signing keys.</p>
<p>### Details</p>
<p>**1. `path` parameter lacks `SanitizeUserPath()` — primary vector (`http/media.go:54`)**</p>
<p>```go
userscope, err := d.user.GetScopeForSourceName(source)
// ...
realPath, _, err := idx.GetRealPath(userscope, path)  // path is raw user input, no sanitization
// ...
parentDir := filepath.Dir(realPath)  // line 59: attacker controls this directory
```</p>
<p>`SanitizeUserPath()` explicitly rejects `..` segments:</p>
<p>```go
func SanitizeUserPath(userPath string) (string, error) {
    // ...
    for _, segment := range segments {
        if segm…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vvp7-h4fj-m28w"/>
  </entry>
</feed>
