<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T06:46:14.129141+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-307814</id>
    <title>EUVD-2026-307814</title>
    <updated>2026-10-07T06:46:14.133271+00:00</updated>
    <content>EUVD-2026-307814</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-307814"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-7317</id>
    <title>fkie_cve-2026-7317</title>
    <updated>2026-10-07T06:46:14.133356+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The manipulation results in deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made public and could be used. Upgrading to version 2.0.0-beta.2 addresses this issue. The patch is identified as c66dfeb5f. The affected component should be upgraded.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-7317"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gwfr-jfjf-92vv</id>
    <title>GHSA-gwfr-jfjf-92vv — Grav has Insecure Deserialization in File Cache</title>
    <updated>2026-10-07T06:46:14.133394+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getgrav/grav</p>
<p># Insecure Deserialization in File Cache</p>
<p>- **Severity:** High 
- **CWE:** CWE-502
- **Location:** `system/src/Grav/Framework/Cache/Adapter/FileCache.php`
- **Sink:** `unserialize($value, ['allowed_classes' =&gt; true])`</p>
<p>## Affected version(s)</p>
<p>- **Affected:** `&gt;= 1.7.44` and `&lt;= 1.7.49.5` (verified in current codebase and changelog-covered releases).
- **Fixed:** No upstream fix identified in the reviewed branch at the time of analysis.
- **Notes:** Earlier `1.7.x` releases may also be affected, but were not fully back-traced in this review.</p>
<p>## Notes
`allowed_classes =&gt; true` allows object instantiation and does not constrain classes.</p>
<p>## PoC (Primitive Demonstration)</p>
<p>### Preconditions
- Local PHP runtime.
- Goal is to validate the deserialization primitive used in cache retrieval.</p>
<p>### Steps
```bash
php -r '
class CacheWakeup { public function __wakeup(){ file_put_contents("/tmp/grav_filecache_poc.txt", "wakeup"); } }</p>
<p>$payload = serialize(new CacheWakeup());
unserialize($payload, ["allowed_classes" =&gt; true]);</p>
<p>echo file_exists("/tmp/grav_filecache_poc.txt") ? "FILECACHE_UNSERIALIZE_TRIGGERED\n" : "FILECACHE_UNSERIALIZE_NOT_TRIGGERED\n";
'
```</p>
<p>### Expected Result
- Output contains: `FILECACHE_UNSERIALIZE_TRIGGERED`.</p>
<p>### Interpretation
This reproduces the same unsafe primitive used by `FileCache::doGet()`:
`unserialize($value, ['allowed_classes' =&gt; true])`.
If cache files are attacker-tampered, object magic methods may execute.</p>
<p>## Exploit Preconditions
- Cache file poiso…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gwfr-jfjf-92vv"/>
  </entry>
</feed>
