<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:03:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-319520</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319520</link>
      <description>EUVD-2026-319520</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319520</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22810</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22810</link>
      <description>&lt;p&gt;Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it&amp;#39;s possible for an attacker to create a malicious .one file that includes file names containing ../../, that are then interpreted as part of the target path when extracting attachments from the .one file. This issue has been patched in version 3.5.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it&amp;#39;s possible for an attacker to create a malicious .one file that includes file names containing ../../, that are then interpreted as part of the target path when extracting attachments from the .one file. This issue has been patched in version 3.5.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22810</guid>
    </item>
    <item>
      <title>GHSA-gcmj-c9gg-9vh6 — @joplin/onenote-converter: Path traversal in OneNote importer allows overwriting arbitrary files</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gcmj-c9gg-9vh6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @joplin/onenote-converter&lt;/p&gt;
&lt;p&gt;### Summary
A path traversal vulnerability in the OneNote importer allows overwriting arbitrary files on disk.&lt;/p&gt;
&lt;p&gt;### Details
The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it&amp;#39;s possible for an attacker to create a malicious `.one` file that includes file names containing `../../`, that are then interpreted as part of the target path when extracting attachments from the `.one` file.&lt;/p&gt;
&lt;p&gt;One affected location is `embedded_file.rs`, which generates a file name from a string previously parsed from the `.one` file,
https://github.com/laurent22/joplin/blob/af5108d70233b1db9410346958c1587cf7c1b16d/packages/onenote-converter/renderer/src/page/embedded_file.rs#L13-L16&lt;/p&gt;
&lt;p&gt;Above, [`determine_filename`](https://github.com/laurent22/joplin/blob/af5108d70233b1db9410346958c1587cf7c1b16d/packages/onenote-converter/renderer/src/page/embedded_file.rs#L56-L64) passes through the provided file name.&lt;/p&gt;
&lt;p&gt;[Similar logic](https://github.com/laurent22/joplin/blob/4d7fa5972fe2986eae14cbf3a2801835cbe1384e/packages/onenote-converter/src/page/embedded_file.rs#L14) has been present since 4d7fa5972fe2986eae14cbf3a2801835cbe1384e (Joplin 3.2.2), when the OneNote importer was first introduced.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;[Screencast from 2025-11-20 13-50-21.webm](https://github.com/user-attachments/assets/a9d6cc64-ec11-4f33-9f92-32efe0eaab23)&lt;/p&gt;
&lt;p&gt;1. Import [poc_v2.zip](https://github.com/user-attachments/files/23664109/poc_v2.zip).
2. Open the application&amp;#39;s profile directo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @joplin/onenote-converter&lt;/p&gt;
&lt;p&gt;### Summary
A path traversal vulnerability in the OneNote importer allows overwriting arbitrary files on disk.&lt;/p&gt;
&lt;p&gt;### Details
The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it&amp;#39;s possible for an attacker to create a malicious `.one` file that includes file names containing `../../`, that are then interpreted as part of the target path when extracting attachments from the `.one` file.&lt;/p&gt;
&lt;p&gt;One affected location is `embedded_file.rs`, which generates a file name from a string previously parsed from the `.one` file,
https://github.com/laurent22/joplin/blob/af5108d70233b1db9410346958c1587cf7c1b16d/packages/onenote-converter/renderer/src/page/embedded_file.rs#L13-L16&lt;/p&gt;
&lt;p&gt;Above, [`determine_filename`](https://github.com/laurent22/joplin/blob/af5108d70233b1db9410346958c1587cf7c1b16d/packages/onenote-converter/renderer/src/page/embedded_file.rs#L56-L64) passes through the provided file name.&lt;/p&gt;
&lt;p&gt;[Similar logic](https://github.com/laurent22/joplin/blob/4d7fa5972fe2986eae14cbf3a2801835cbe1384e/packages/onenote-converter/src/page/embedded_file.rs#L14) has been present since 4d7fa5972fe2986eae14cbf3a2801835cbe1384e (Joplin 3.2.2), when the OneNote importer was first introduced.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;[Screencast from 2025-11-20 13-50-21.webm](https://github.com/user-attachments/assets/a9d6cc64-ec11-4f33-9f92-32efe0eaab23)&lt;/p&gt;
&lt;p&gt;1. Import [poc_v2.zip](https://github.com/user-attachments/files/23664109/poc_v2.zip).
2. Open the application&amp;#39;s profile directo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gcmj-c9gg-9vh6</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1569 — Joplin: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1569</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Joplin ausnutzen, um einen Denial of Service Angriff durchzuführen, vertrauliche Informationen offenzulegen oder beliebige Dateien zu überschreiben, was möglicherweise zur Ausführung von beliebigem Code führt.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Joplin ausnutzen, um einen Denial of Service Angriff durchzuführen, vertrauliche Informationen offenzulegen oder beliebige Dateien zu überschreiben, was möglicherweise zur Ausführung von beliebigem Code führt.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1569</guid>
    </item>
  </channel>
</rss>
