<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T10:02:29.440314+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354589</id>
    <title>EUVD-2026-354589</title>
    <updated>2026-10-07T10:02:29.486097+00:00</updated>
    <content>EUVD-2026-354589</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354589"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63667</id>
    <title>fkie_cve-2026-63667</title>
    <updated>2026-10-07T10:02:29.486134+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and extension fields in aposAttachments.json without ensuring that the resolved path remains under the extracted attachments directory, allowing an authenticated contributor to import a crafted archive, read a host file with an allowed extension, and publish the copied file at an unauthenticated uploads URL. This issue is fixed in version 3.6.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-79qf-vqgc-7xx3</id>
    <title>GHSA-79qf-vqgc-7xx3 — ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal</title>
    <updated>2026-10-07T10:02:29.486170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @apostrophecms/import-export</p>
<p>## Summary</p>
<p>The `@apostrophecms/import-export` module reconstructs the on-disk source path of every imported attachment from JSON metadata contained in the uploaded archive.</p>
<p>The archive carries an `aposAttachments.json` file whose `name` and `extension` fields are concatenated into a filesystem path with no traversal check. The zip-slip guard that the module applies during tar extraction validates tar entry names only and does not cover this second path, which is built after extraction.</p>
<p>The file at the resulting path is read and copied into the public uploads directory, then served over HTTP without authentication. A `../` sequence in `name` makes the module read a file outside the extraction directory and publish it at an anonymous URL.</p>
<p>Result: an authenticated contributor reads any file on the host whose name ends in an allowlisted extension (other users' uploaded documents, text or CSV dumps, PDFs) by importing a crafted archive and fetching the planted attachment anonymously.</p>
<p>## Affected</p>
<p>apostrophecms/apostrophe with the `@apostrophecms/import-export` module installed and registered. Module version 3.6.1 (current latest), tested against Apostrophe 4.31.0 (monorepo HEAD 4d478d9). Requires an account with the contributor role or higher; guest and anonymous requests are rejected. The module is not part of the default starter kit, so sites that never installed it are not affected. Files whose real name lacks an accepted file-group extension are not reachable.</p>
<p>## Root c…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-79qf-vqgc-7xx3"/>
  </entry>
</feed>
