<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:04:17 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10662</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10662</link>
      <description>bdu:2026-10662</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10662</guid>
    </item>
    <item>
      <title>EUVD-2026-270764</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-270764</link>
      <description>EUVD-2026-270764</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-270764</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27641</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27641</link>
      <description>&lt;p&gt;Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI). Flask-Reuploaded has been patched in version 1.5.0. Some workarounds are available. Do not pass user input to the `name` parameter, use auto-generated filenames only, and implement strict input validation if `name` must be used.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI). Flask-Reuploaded has been patched in version 1.5.0. Some workarounds are available. Do not pass user input to the `name` parameter, use auto-generated filenames only, and implement strict input validation if `name` must be used.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27641</guid>
    </item>
    <item>
      <title>GHSA-65mp-fq8v-56jr — Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-65mp-fq8v-56jr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: flask-reuploaded&lt;/p&gt;
&lt;p&gt;### Impact
A critical path traversal and extension bypass vulnerability in Flask-Reuploaded allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI).&lt;/p&gt;
&lt;p&gt;### Patches
Flask-Reuploaded has been patched in version 1.5.0&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;1. **Do not pass user input to the `name` parameter**
2. Use auto-generated filenames only
3. Implement strict input validation if `name` must be used&lt;/p&gt;
&lt;p&gt;```python
from werkzeug.utils import secure_filename
import os&lt;/p&gt;
&lt;p&gt;# Sanitize user input before passing to save()
safe_name = secure_filename(request.form.get(&amp;#39;custom_name&amp;#39;))
# Remove path separators
safe_name = os.path.basename(safe_name)
# Validate extension matches policy
if not photos.extension_allowed(photos.get_extension(safe_name)):
    abort(400)
    
filename = photos.save(file, name=safe_name)
```&lt;/p&gt;
&lt;p&gt;### Resources
The fix is documented in the pull request, see https://github.com/jugmac00/flask-reuploaded/pull/180.&lt;/p&gt;
&lt;p&gt;A proper write-up was created by the reporter of the vulnerability, Jaron Cabral (https://www.linkedin.com/in/jaron-cabral-751994357/), but is not yet available as of time of this publication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: flask-reuploaded&lt;/p&gt;
&lt;p&gt;### Impact
A critical path traversal and extension bypass vulnerability in Flask-Reuploaded allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI).&lt;/p&gt;
&lt;p&gt;### Patches
Flask-Reuploaded has been patched in version 1.5.0&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;1. **Do not pass user input to the `name` parameter**
2. Use auto-generated filenames only
3. Implement strict input validation if `name` must be used&lt;/p&gt;
&lt;p&gt;```python
from werkzeug.utils import secure_filename
import os&lt;/p&gt;
&lt;p&gt;# Sanitize user input before passing to save()
safe_name = secure_filename(request.form.get(&amp;#39;custom_name&amp;#39;))
# Remove path separators
safe_name = os.path.basename(safe_name)
# Validate extension matches policy
if not photos.extension_allowed(photos.get_extension(safe_name)):
    abort(400)
    
filename = photos.save(file, name=safe_name)
```&lt;/p&gt;
&lt;p&gt;### Resources
The fix is documented in the pull request, see https://github.com/jugmac00/flask-reuploaded/pull/180.&lt;/p&gt;
&lt;p&gt;A proper write-up was created by the reporter of the vulnerability, Jaron Cabral (https://www.linkedin.com/in/jaron-cabral-751994357/), but is not yet available as of time of this publication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-65mp-fq8v-56jr</guid>
    </item>
    <item>
      <title>PYSEC-2026-341 — Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-341</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: flask-reuploaded&lt;/p&gt;
&lt;p&gt;### Impact
A critical path traversal and extension bypass vulnerability in Flask-Reuploaded allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI).&lt;/p&gt;
&lt;p&gt;### Patches
 Flask-Reuploaded has been patched in version 1.5.0&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;1. **Do not pass user input to the `name` parameter**
2. Use auto-generated filenames only
 3. Implement strict input validation if `name` must be used&lt;/p&gt;
&lt;p&gt;```python
from werkzeug.utils import secure_filename
import os&lt;/p&gt;
&lt;p&gt;# Sanitize user input before passing to save()
 safe_name = secure_filename(request.form.get(&amp;#39;custom_name&amp;#39;))
# Remove path separators
 safe_name = os.path.basename(safe_name)
# Validate extension matches policy
if not photos.extension_allowed(photos.get_extension(safe_name)):
    abort(400)
    
filename = photos.save(file, name=safe_name)
```&lt;/p&gt;
&lt;p&gt;### Resources
The fix is documented in the pull request, see https://github.com/jugmac00/flask-reuploaded/pull/180.
 
A proper write-up was created by the reporter of the vulnerability, Jaron Cabral (https://www.linkedin.com/in/jaron-cabral-751994357/), but is not yet available as of time of this publication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: flask-reuploaded&lt;/p&gt;
&lt;p&gt;### Impact
A critical path traversal and extension bypass vulnerability in Flask-Reuploaded allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI).&lt;/p&gt;
&lt;p&gt;### Patches
 Flask-Reuploaded has been patched in version 1.5.0&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;1. **Do not pass user input to the `name` parameter**
2. Use auto-generated filenames only
 3. Implement strict input validation if `name` must be used&lt;/p&gt;
&lt;p&gt;```python
from werkzeug.utils import secure_filename
import os&lt;/p&gt;
&lt;p&gt;# Sanitize user input before passing to save()
 safe_name = secure_filename(request.form.get(&amp;#39;custom_name&amp;#39;))
# Remove path separators
 safe_name = os.path.basename(safe_name)
# Validate extension matches policy
if not photos.extension_allowed(photos.get_extension(safe_name)):
    abort(400)
    
filename = photos.save(file, name=safe_name)
```&lt;/p&gt;
&lt;p&gt;### Resources
The fix is documented in the pull request, see https://github.com/jugmac00/flask-reuploaded/pull/180.
 
A proper write-up was created by the reporter of the vulnerability, Jaron Cabral (https://www.linkedin.com/in/jaron-cabral-751994357/), but is not yet available as of time of this publication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-341</guid>
    </item>
  </channel>
</rss>
