<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T02:18:14.504587+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338075</id>
    <title>EUVD-2026-338075</title>
    <updated>2026-10-06T02:18:14.548832+00:00</updated>
    <content>EUVD-2026-338075</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-62843</id>
    <title>fkie_cve-2026-62843</title>
    <updated>2026-10-06T02:18:14.548872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as ..\..\evil.sh into the archive entry ../../evil.sh, allowing a user with upload permission to plant a backslash-named file that escapes the extraction directory when another user downloads and extracts the generated zip or tar archive. This issue is fixed in version 2.63.17.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-62843"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-83xp-526h-j3ww</id>
    <title>GHSA-83xp-526h-j3ww — File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)</title>
    <updated>2026-10-06T02:18:14.548909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/filebrowser/filebrowser/v2</p>
<p>## Summary</p>
<p>The fix for `GHSA-gxjx-7m74-hcq8` / `CVE-2026-54093` (shipped in v2.63.6) added a `strings.ReplaceAll(nameInArchive, "\\", "/")` step to the archive builder; this was the advisory's recommended "Primary Fix." On a Linux host a backslash is a legal, non-separator filename character, so replacing it with the real POSIX separator `/` **manufactures** a `/`-delimited traversal sequence out of a benign single file name. The fix neutralized the Windows-only vector but reintroduced the same class of bug on POSIX systems, and the advisory's "Secondary Mitigation" (reject backslash filenames at creation time) was never implemented, so the malicious file can still be planted.</p>
<p>A file named `..\..\evil.sh`, one ordinary regular file on a Linux server, is emitted into generated zip/tar archives as the entry `../../evil.sh`. Any user with upload (Create) permission can plant such a file; when anyone later downloads the containing folder as an archive and extracts it, the entry escapes the extraction directory on the victim's machine. The original advisory's own payload `..\..\..\Windows\System32\evil.txt` now becomes `../../../Windows/System32/evil.txt`, which, unlike before the fix, also traverses on Linux and macOS extractors. The fix turned a Windows-only zip-slip into a cross-platform one.</p>
<p>## Details</p>
<p>**1. The archive builder rewrites backslashes into path separators (`http/raw.go:133`)**</p>
<p>```go
nameInArchive := strings.TrimPrefix(path, commonPath)
nameInArchive = string…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-83xp-526h-j3ww"/>
  </entry>
</feed>
