<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:40:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-2824</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-2824</link>
      <description>EUVD-2026-2824</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-2824</guid>
    </item>
    <item>
      <title>fkie_cve-2024-5023</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-5023</link>
      <description>&lt;p&gt;Improper Neutralization of Special Elements used in a Command (&amp;#39;Command Injection&amp;#39;) vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Neutralization of Special Elements used in a Command (&amp;#39;Command Injection&amp;#39;) vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-5023</guid>
    </item>
    <item>
      <title>GHSA-3783-62vc-jr7x — ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3783-62vc-jr7x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: consoleme&lt;/p&gt;
&lt;p&gt;## ID: NFLX-2024-002&lt;/p&gt;
&lt;p&gt;### Impact
Authenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. 
However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe&amp;#39;s role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation.&lt;/p&gt;
&lt;p&gt;Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected.&lt;/p&gt;
&lt;p&gt;To determine if your ConsoleMe deployment uses templated resources, check the configuration value for `cache_resource_templates.repositories`. If this value does not exist or is an empty array, your deployment is not impacted.
### Description
The self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process.&lt;/p&gt;
&lt;p&gt;### Patches
This iss…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: consoleme&lt;/p&gt;
&lt;p&gt;## ID: NFLX-2024-002&lt;/p&gt;
&lt;p&gt;### Impact
Authenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. 
However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe&amp;#39;s role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation.&lt;/p&gt;
&lt;p&gt;Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected.&lt;/p&gt;
&lt;p&gt;To determine if your ConsoleMe deployment uses templated resources, check the configuration value for `cache_resource_templates.repositories`. If this value does not exist or is an empty array, your deployment is not impacted.
### Description
The self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process.&lt;/p&gt;
&lt;p&gt;### Patches
This iss…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3783-62vc-jr7x</guid>
    </item>
    <item>
      <title>PYSEC-2026-318 — ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-318</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: consoleme&lt;/p&gt;
&lt;p&gt;## ID: NFLX-2024-002&lt;/p&gt;
&lt;p&gt;### Impact
Authenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. 
However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe&amp;#39;s role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation.&lt;/p&gt;
&lt;p&gt;Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected.&lt;/p&gt;
&lt;p&gt;To determine if your ConsoleMe deployment uses templated resources, check the configuration value for `cache_resource_templates.repositories`. If this value does not exist or is an empty array, your deployment is not impacted.
### Description
The self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process.&lt;/p&gt;
&lt;p&gt;### Patches
This iss…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: consoleme&lt;/p&gt;
&lt;p&gt;## ID: NFLX-2024-002&lt;/p&gt;
&lt;p&gt;### Impact
Authenticated users can achieve limited RCE in ConsoleMe, restricted to flag inputs on a single CLI command. Due to this constraint, it is not currently known whether full RCE is possible but it is unlikely. 
However, a specific flag allows authenticated users to read any server files accessible by the ConsoleMe process. Given ConsoleMe&amp;#39;s role as an AWS identity broker, accessing files containing secrets on the server could potentially be exploited for privilege escalation.&lt;/p&gt;
&lt;p&gt;Deployments of ConsoleMe that allow templated resources are impacted and urged to patch immediately. Deployments that do not permit templated resources are not affected.&lt;/p&gt;
&lt;p&gt;To determine if your ConsoleMe deployment uses templated resources, check the configuration value for `cache_resource_templates.repositories`. If this value does not exist or is an empty array, your deployment is not impacted.
### Description
The self-service flow for templated resources in ConsoleMe accepts a user-supplied JSON post body, which includes the filename for the templated resource. However, this user-supplied filename is not properly sanitized and is passed directly as a string to a CLI command. This allows users to input flags instead of filenames. By passing a specific flag with a filename value, users can induce an error that reveals the contents of the specified file, allowing them to read any files readable by the system user executing the ConsoleMe server process.&lt;/p&gt;
&lt;p&gt;### Patches
This iss…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-318</guid>
    </item>
  </channel>
</rss>
