<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 06:27:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-4741</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-4741</link>
      <description>EUVD-2026-4741</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-4741</guid>
    </item>
    <item>
      <title>fkie_cve-2024-30265</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-30265</link>
      <description>&lt;p&gt;Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-30265</guid>
    </item>
    <item>
      <title>GHSA-2q59-h24c-w6fg — Voilà Local file inclusion</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2q59-h24c-w6fg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: voila&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Any deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server.&lt;/p&gt;
&lt;p&gt;Whether this still requires authentication depends on how voilà is deployed.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;CWE-73: External Control of File Name or Path&lt;/p&gt;
&lt;p&gt;### Original report&lt;/p&gt;
&lt;p&gt;I have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila).&lt;/p&gt;
&lt;p&gt;The vulnerability exists in the &amp;#34;/static&amp;#34; Route, and can be exploited by simply making a request such as this:&lt;/p&gt;
&lt;p&gt;```
$ curl localhost:8866/static/etc/passwd
```&lt;/p&gt;
&lt;p&gt;...or by using a webbrowser to download the file.&lt;/p&gt;
&lt;p&gt;I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
`&amp;#34;static_path&amp;#34;` gets set to `&amp;#34;/&amp;#34;`, irrespective of the actual `&amp;#34;--static&amp;#34;` cli option. Because of that, the `tornado.web.StaticFileHandler` gets initialized with `path=&amp;#34;/&amp;#34;`. Then, `tornado.web.StaticFileHandler.get` calls `tornado.web.StaticFileHandler.get_absolute_path` with `root=&amp;#34;/&amp;#34;` and `path=&amp;#34;[USER SUPPLIED PATH]&amp;#34;`, which leads to local file inclusion. An attacker can request any file on the system they want (that the user running voila has access to).&lt;/p&gt;
&lt;p&gt;I suspect this was an…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: voila&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Any deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server.&lt;/p&gt;
&lt;p&gt;Whether this still requires authentication depends on how voilà is deployed.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;CWE-73: External Control of File Name or Path&lt;/p&gt;
&lt;p&gt;### Original report&lt;/p&gt;
&lt;p&gt;I have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila).&lt;/p&gt;
&lt;p&gt;The vulnerability exists in the &amp;#34;/static&amp;#34; Route, and can be exploited by simply making a request such as this:&lt;/p&gt;
&lt;p&gt;```
$ curl localhost:8866/static/etc/passwd
```&lt;/p&gt;
&lt;p&gt;...or by using a webbrowser to download the file.&lt;/p&gt;
&lt;p&gt;I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
`&amp;#34;static_path&amp;#34;` gets set to `&amp;#34;/&amp;#34;`, irrespective of the actual `&amp;#34;--static&amp;#34;` cli option. Because of that, the `tornado.web.StaticFileHandler` gets initialized with `path=&amp;#34;/&amp;#34;`. Then, `tornado.web.StaticFileHandler.get` calls `tornado.web.StaticFileHandler.get_absolute_path` with `root=&amp;#34;/&amp;#34;` and `path=&amp;#34;[USER SUPPLIED PATH]&amp;#34;`, which leads to local file inclusion. An attacker can request any file on the system they want (that the user running voila has access to).&lt;/p&gt;
&lt;p&gt;I suspect this was an…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2q59-h24c-w6fg</guid>
    </item>
    <item>
      <title>gsd-2024-30265</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-30265</link>
      <description>gsd-2024-30265</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-30265</guid>
    </item>
    <item>
      <title>PYSEC-2026-2027 — Voilà Local file inclusion</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2027</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: voila&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Any deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server.&lt;/p&gt;
&lt;p&gt;Whether this still requires authentication depends on how voilà is deployed.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;CWE-73: External Control of File Name or Path&lt;/p&gt;
&lt;p&gt;### Original report&lt;/p&gt;
&lt;p&gt;I have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila).&lt;/p&gt;
&lt;p&gt;The vulnerability exists in the &amp;#34;/static&amp;#34; Route, and can be exploited by simply making a request such as this:&lt;/p&gt;
&lt;p&gt;```
$ curl localhost:8866/static/etc/passwd
```&lt;/p&gt;
&lt;p&gt;...or by using a webbrowser to download the file.&lt;/p&gt;
&lt;p&gt;I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
`&amp;#34;static_path&amp;#34;` gets set to `&amp;#34;/&amp;#34;`, irrespective of the actual `&amp;#34;--static&amp;#34;` cli option. Because of that, the `tornado.web.StaticFileHandler` gets initialized with `path=&amp;#34;/&amp;#34;`. Then, `tornado.web.StaticFileHandler.get` calls `tornado.web.StaticFileHandler.get_absolute_path` with `root=&amp;#34;/&amp;#34;` and `path=&amp;#34;[USER SUPPLIED PATH]&amp;#34;`, which leads to local file inclusion. An attacker can request any file on the system they want (that the user running voila has access to).&lt;/p&gt;
&lt;p&gt;I suspect this was an…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: voila&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Any deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server.&lt;/p&gt;
&lt;p&gt;Whether this still requires authentication depends on how voilà is deployed.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;CWE-73: External Control of File Name or Path&lt;/p&gt;
&lt;p&gt;### Original report&lt;/p&gt;
&lt;p&gt;I have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila).&lt;/p&gt;
&lt;p&gt;The vulnerability exists in the &amp;#34;/static&amp;#34; Route, and can be exploited by simply making a request such as this:&lt;/p&gt;
&lt;p&gt;```
$ curl localhost:8866/static/etc/passwd
```&lt;/p&gt;
&lt;p&gt;...or by using a webbrowser to download the file.&lt;/p&gt;
&lt;p&gt;I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
`&amp;#34;static_path&amp;#34;` gets set to `&amp;#34;/&amp;#34;`, irrespective of the actual `&amp;#34;--static&amp;#34;` cli option. Because of that, the `tornado.web.StaticFileHandler` gets initialized with `path=&amp;#34;/&amp;#34;`. Then, `tornado.web.StaticFileHandler.get` calls `tornado.web.StaticFileHandler.get_absolute_path` with `root=&amp;#34;/&amp;#34;` and `path=&amp;#34;[USER SUPPLIED PATH]&amp;#34;`, which leads to local file inclusion. An attacker can request any file on the system they want (that the user running voila has access to).&lt;/p&gt;
&lt;p&gt;I suspect this was an…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2027</guid>
    </item>
  </channel>
</rss>
