<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:06:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-223758</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-223758</link>
      <description>EUVD-2026-223758</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-223758</guid>
    </item>
    <item>
      <title>fkie_cve-2025-26260</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-26260</link>
      <description>&lt;p&gt;Plenti &amp;lt;= 0.7.16 is vulnerable to code execution. Users uploading &amp;#39;.svelte&amp;#39; files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Plenti &amp;lt;= 0.7.16 is vulnerable to code execution. Users uploading &amp;#39;.svelte&amp;#39; files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-26260</guid>
    </item>
    <item>
      <title>GHSA-mj4v-hp69-27x5 — Plenti  - Code Injection - Denial of Services</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mj4v-hp69-27x5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/plentico/plenti&lt;/p&gt;
&lt;p&gt;### Summary
While pushing a file via postLocal method if user add javascript code in file parameter that codes can exe in v8go context.&lt;/p&gt;
&lt;p&gt;### Details
While posting a file via postLocal, any attacker will add javascript codes to file parameter. That parameter content pass to componentSignature method after some validation. After that componentSignature parameter concat with ssrStr parameter.&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1145&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a08a3fe5-2fbd-4a05-b93c-2ad127e6ee81&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Last part of compileSvelte function ssrStr parameter executed in v8go engine.&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;754&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/4e622761-3324-48d6-8264-6dd6e09055af&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;This cause to any one who can post a file also can push javascript code and run it. Thanks to v8go we can&amp;#39;t use all javascript metod, if there is no any vulnerability in v8go we can&amp;#39;t escape sandbox and can&amp;#39;t run dangerous command like opening socket etc. But we can create infinite loop and the plenti can&amp;#39;t response any request.&lt;/p&gt;
&lt;p&gt;After posting a file with name &amp;#39;layouts/global/test; eval(`while(1);`);var test.svelte&amp;#39; we can see the ssrStr parameter include our javascript codes.&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1023&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/369c7820-ff8a-4b9a-9cd3-6b0692f1dcf3&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;**Note**: Eval usage not must I just want to ensure that it&amp;#39;s run javascript commands.&lt;/p&gt;
&lt;p&gt;### PoC
**Request**
```
POST /postlocal HTTP/1.1
Host: localhost:3000
Content-Length: 125
Conten…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/plentico/plenti&lt;/p&gt;
&lt;p&gt;### Summary
While pushing a file via postLocal method if user add javascript code in file parameter that codes can exe in v8go context.&lt;/p&gt;
&lt;p&gt;### Details
While posting a file via postLocal, any attacker will add javascript codes to file parameter. That parameter content pass to componentSignature method after some validation. After that componentSignature parameter concat with ssrStr parameter.&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1145&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a08a3fe5-2fbd-4a05-b93c-2ad127e6ee81&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Last part of compileSvelte function ssrStr parameter executed in v8go engine.&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;754&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/4e622761-3324-48d6-8264-6dd6e09055af&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;This cause to any one who can post a file also can push javascript code and run it. Thanks to v8go we can&amp;#39;t use all javascript metod, if there is no any vulnerability in v8go we can&amp;#39;t escape sandbox and can&amp;#39;t run dangerous command like opening socket etc. But we can create infinite loop and the plenti can&amp;#39;t response any request.&lt;/p&gt;
&lt;p&gt;After posting a file with name &amp;#39;layouts/global/test; eval(`while(1);`);var test.svelte&amp;#39; we can see the ssrStr parameter include our javascript codes.&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1023&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/369c7820-ff8a-4b9a-9cd3-6b0692f1dcf3&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;**Note**: Eval usage not must I just want to ensure that it&amp;#39;s run javascript commands.&lt;/p&gt;
&lt;p&gt;### PoC
**Request**
```
POST /postlocal HTTP/1.1
Host: localhost:3000
Content-Length: 125
Conten…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mj4v-hp69-27x5</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14893-1 — govulncheck-vulndb-0.0.20250313T170021-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14893-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250313T170021-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250313T170021-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14893-1</guid>
    </item>
  </channel>
</rss>
