<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 11:01:04 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265722</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265722</link>
      <description>EUVD-2026-265722</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265722</guid>
    </item>
    <item>
      <title>fkie_cve-2025-59342</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59342</link>
      <description>&lt;p&gt;esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a filesystem path but is not properly canonicalized or restricted to the application’s storage base directory. As a result, supplying ../ sequences in X-Zone-Id causes files to be written to arbitrary directories. Version 136.1 contains a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a filesystem path but is not properly canonicalized or restricted to the application’s storage base directory. As a result, supplying ../ sequences in X-Zone-Id causes files to be written to arbitrary directories. Version 136.1 contains a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-59342</guid>
    </item>
    <item>
      <title>GHSA-g2h5-cvvr-7gmw — esm.sh has arbitrary file write via path traversal in `X-Zone-Id` header</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g2h5-cvvr-7gmw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/esm-dev/esm.sh&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A path-traversal flaw in the handling of the `X-Zone-Id` HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a filesystem path but is not properly canonicalized or restricted to the application’s storage base directory. As a result, supplying `../` sequences in `X-Zone-Id` causes files to be written to arbitrary directories (example observed: `~/.esmd/modules/transform/&amp;lt;id&amp;gt;/` instead of `~/.esmd/storage/modules/transform`).&lt;/p&gt;
&lt;p&gt;**Severity:** Medium&lt;/p&gt;
&lt;p&gt;**Component / Endpoint:**&lt;/p&gt;
&lt;p&gt;`POST /transform` — handling of `X-Zone-Id` header&lt;/p&gt;
&lt;p&gt;The vulnerable code is in https://github.com/esm-dev/esm.sh/blob/main/server/router.go#L116 and https://github.com/esm-dev/esm.sh/blob/main/server/router.go#L411&lt;/p&gt;
&lt;p&gt;**Impact:** Arbitrary file creation / overwrite outside intended storage directory (file write to attacker-controlled path). Possible remote code execution, persistence, tampering with application files, or facilitating further path-traversal attacks.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Proof of Concept (POC)&lt;/p&gt;
&lt;p&gt;Request (attacker-supplied `X-Zone-Id` contains path traversal):&lt;/p&gt;
&lt;p&gt;```
POST /transform HTTP/1.1
Host: localhost:8888
User-Agent: Den/8.7.1
Accept: */*
Connection: keep-alive
Referer: http://localhost:9999/
Content-Type: application/json
X-Zone-Id: ../../modules/transform/c245626ef6ca0fd9ee37759c5fac606c6ec99daa/
Content-Length: 325&lt;/p&gt;
&lt;p&gt;{
  &amp;#34;filename&amp;#34;: &amp;#34;example2.js&amp;#34;,
  &amp;#34;lang&amp;#34;: &amp;#34;js&amp;#34;,
  &amp;#34;code&amp;#34;: &amp;#34;console.log(&amp;#39;hello&amp;#39;);&amp;#34;,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/esm-dev/esm.sh&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A path-traversal flaw in the handling of the `X-Zone-Id` HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a filesystem path but is not properly canonicalized or restricted to the application’s storage base directory. As a result, supplying `../` sequences in `X-Zone-Id` causes files to be written to arbitrary directories (example observed: `~/.esmd/modules/transform/&amp;lt;id&amp;gt;/` instead of `~/.esmd/storage/modules/transform`).&lt;/p&gt;
&lt;p&gt;**Severity:** Medium&lt;/p&gt;
&lt;p&gt;**Component / Endpoint:**&lt;/p&gt;
&lt;p&gt;`POST /transform` — handling of `X-Zone-Id` header&lt;/p&gt;
&lt;p&gt;The vulnerable code is in https://github.com/esm-dev/esm.sh/blob/main/server/router.go#L116 and https://github.com/esm-dev/esm.sh/blob/main/server/router.go#L411&lt;/p&gt;
&lt;p&gt;**Impact:** Arbitrary file creation / overwrite outside intended storage directory (file write to attacker-controlled path). Possible remote code execution, persistence, tampering with application files, or facilitating further path-traversal attacks.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Proof of Concept (POC)&lt;/p&gt;
&lt;p&gt;Request (attacker-supplied `X-Zone-Id` contains path traversal):&lt;/p&gt;
&lt;p&gt;```
POST /transform HTTP/1.1
Host: localhost:8888
User-Agent: Den/8.7.1
Accept: */*
Connection: keep-alive
Referer: http://localhost:9999/
Content-Type: application/json
X-Zone-Id: ../../modules/transform/c245626ef6ca0fd9ee37759c5fac606c6ec99daa/
Content-Length: 325&lt;/p&gt;
&lt;p&gt;{
  &amp;#34;filename&amp;#34;: &amp;#34;example2.js&amp;#34;,
  &amp;#34;lang&amp;#34;: &amp;#34;js&amp;#34;,
  &amp;#34;code&amp;#34;: &amp;#34;console.log(&amp;#39;hello&amp;#39;);&amp;#34;,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g2h5-cvvr-7gmw</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15576-1 — govulncheck-vulndb-0.0.20250924T192141-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15576-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250924T192141-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250924T192141-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15576-1</guid>
    </item>
  </channel>
</rss>
