<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T21:47:00.462750+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355100</id>
    <title>EUVD-2026-355100</title>
    <updated>2026-10-07T21:47:00.513849+00:00</updated>
    <content>EUVD-2026-355100</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-62684</id>
    <title>fkie_cve-2026-62684</title>
    <updated>2026-10-07T21:47:00.513896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandler, and shareGetsHandler through renderJSON, causing POST /api/share/{path} and GET /api/shares to expose password_hash and the bypass token, while an administrator can retrieve these secrets for every user's shares, enabling offline password cracking and direct access to protected shares. This issue is fixed in version 2.63.17.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-62684"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-833g-cqhp-h72j</id>
    <title>GHSA-833g-cqhp-h72j — File Browser: Share API exposes the password hash and bypass token</title>
    <updated>2026-10-07T21:47:00.513934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/filebrowser/filebrowser/v2</p>
<p>## Summary</p>
<p>When a user creates a password-protected share or lists existing shares, the JSON response includes the full bcrypt `password_hash` and the secret `token` of the share. The `Link` storage struct is serialized directly with `json.Marshal` and tags `password_hash` and `token` for output, with no field filtering. Any authenticated user receives these secrets for their own shares, and an administrator listing all shares via `GET /api/shares` receives the password hash and bypass token for **every** user's shares, enabling offline cracking of share passwords and direct password-bypass access to protected shares.</p>
<p>## Details</p>
<p>**1. The `Link` struct serializes both secrets to JSON (`share/share.go:10-19`)**</p>
<p>```go
type Link struct {
    Hash         string `json:"hash" storm:"id,index"`
    Path         string `json:"path" storm:"index"`
    UserID       uint   `json:"userID"`
    Expire       int64  `json:"expire"`
    PasswordHash string `json:"password_hash,omitempty"`   // line 15, bcrypt hash exposed
    // Token is only set when PasswordHash is set; it bypasses the password.
    Token        string `json:"token,omitempty"`            // line 19, bypass token exposed
}
```</p>
<p>`omitempty` means the hash and token are emitted whenever a share is password-protected, i.e. in every response for such a share.</p>
<p>**2. The share handlers return the full struct through unfiltered `json.Marshal`**</p>
<p>`sharePostHandler` returns the created `Link` with `renderJSON(w, r, s)` (`http/s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-833g-cqhp-h72j"/>
  </entry>
</feed>
