<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:01:26.787022+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-363645</id>
    <title>EUVD-2026-363645</title>
    <updated>2026-10-06T09:01:26.888403+00:00</updated>
    <content>EUVD-2026-363645</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-363645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84374</id>
    <title>fkie_cve-2026-84374</title>
    <updated>2026-10-06T09:01:26.888443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $export-&gt;store(), or storeExcel() against the process working directory with realpath() instead of the configured filesystem disk. If the path names an existing writable file, Disk::copy() opens it with fopen() in rb+ mode and uses stream_copy_to_stream(), bypassing Flysystem path confinement and allowing an attacker whose application input controls the export path to overwrite arbitrary existing files with export content. The rb+ behavior creates a non-truncating overwrite and trailing bytes when the new export is shorter, and overwriting an executable PHP file can lead to remote code execution. This issue is fixed in version 3.1.70.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-84374"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c7r6-vx3h-w5g2</id>
    <title>GHSA-c7r6-vx3h-w5g2 — Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path</title>
    <updated>2026-10-06T09:01:26.888484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: maatwebsite/excel</p>
<p>### Summary</p>
<p>`Excel::store()` resolved the destination path against the process working
directory rather than the configured filesystem disk. When that path resolved to
an existing file, the export was written straight to it with `fopen()`,
bypassing the disk entirely. An application that passes a user-controlled value
as the export path could therefore be made to overwrite an arbitrary existing
file that the PHP process can write to, with content the user controls.</p>
<p>### Details</p>
<p>`Maatwebsite\Excel\Files\Disk::copy()` contained two paths:</p>
<p>```php
if (realpath($destination)) {
    $tempStream = fopen($destination, 'rb+');
    $success    = stream_copy_to_stream($readStream, $tempStream) !== false;
} else {
    $success = $this-&gt;put($destination, $readStream);
}
```</p>
<p>`$destination` is the `$filePath` argument given to `Excel::store()`,
`$export-&gt;store()` or `-&gt;storeExcel()`. `realpath()` resolves it against the
**current working directory** — `public/` for a typical web request — not
against the disk root. On a hit, the write went directly to the filesystem and
never reached Flysystem, which would otherwise have rejected `../` traversal and
confined absolute paths to the disk root. The disk argument was effectively
ignored for those paths, including for remote disks such as S3.</p>
<p>Two consequences follow:</p>
<p>* the destination could be any existing file the PHP process can write, in or
  out of the disk root;
* the stream was opened `'rb+'`, which does not truncate, so a shorter ex…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c7r6-vx3h-w5g2"/>
  </entry>
</feed>
