<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T23:11:26.936479+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352088</id>
    <title>EUVD-2026-352088</title>
    <updated>2026-10-09T23:11:26.983335+00:00</updated>
    <content>EUVD-2026-352088</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73505</id>
    <title>fkie_cve-2026-73505</title>
    <updated>2026-10-09T23:11:26.983377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name containing a Go template expression could execute arbitrary operating system commands as the current user whenever the prompt rendered inside that directory or a descendant. This issue is fixed in version 29.35.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6xj8-qv9j-xcjq</id>
    <title>GHSA-6xj8-qv9j-xcjq — Oh My Posh: Arbitrary command execution via template injection in the path segment</title>
    <updated>2026-10-09T23:11:26.983411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/jandedobbeleer/oh-my-posh</p>
<p>### Summary
Oh My Posh re-renders the resolved path string, which contains the raw folder names taken from the filesystem, through the Go `text/template` engine. That engine's function map exposes a `cmd` function that runs arbitrary OS commands. A directory whose name contains a Go template expression is therefore evaluated when the prompt renders, giving arbitrary command execution as the current user as soon as the shell is inside (or below) that directory. The built-in default configuration is affected.</p>
<p>### Details
`src/segments/path.go`, `setStyle()`:</p>
<p>```go
// make sure we resolve all templates
if txt, err := template.Render(pt.Path, pt); err == nil {
    pt.Path = txt
}
```</p>
<p>`pt.Path` is built from the raw folder-name components of the current working directory (`colorizePath` inserts each folder name verbatim via `fmt.Sprintf(folderFormat, element)`). The whole string is then passed to `template.Render`, which parses and executes it with the full function map from `src/template/func_map.go`, including:</p>
<p>```go
func cmd(command string, args ...string) (string, error) {
    output, err := env.RunCommand(command, args...)
    return strings.TrimSpace(output), err
}
```</p>
<p>Any template syntax present in an untrusted folder name is evaluated. The render runs after the path-style switch unconditionally, so every path style is affected, and the default config (`src/config/default.go`) contains a path segment.</p>
<p>### PoC
Config (a single default path segment):</p>
<p>```json
{ "versio…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6xj8-qv9j-xcjq"/>
  </entry>
</feed>
