<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:43:31 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-338334</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338334</link>
      <description>EUVD-2026-338334</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338334</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45695</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45695</link>
      <description>&lt;p&gt;Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia&amp;#39;s HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments containing -oProxyCommand=&amp;lt;cmd&amp;gt; can cause exec.CommandContext(&amp;#34;ssh&amp;#34;) to invoke the command through OpenSSH. This issue is fixed in version 0.23.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia&amp;#39;s HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments containing -oProxyCommand=&amp;lt;cmd&amp;gt; can cause exec.CommandContext(&amp;#34;ssh&amp;#34;) to invoke the command through OpenSSH. This issue is fixed in version 0.23.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45695</guid>
    </item>
    <item>
      <title>GHSA-2q4c-3mrw-63c3 — Kopia: RCE via SSH ProxyCommand Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2q4c-3mrw-63c3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/kopia/kopia&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Kopia&amp;#39;s HTTP server, when started with `--without-password `, accepts unauthenticated requests to `/api/v1/repo/exists`. The handler forwards an attacker-supplied storage configuration to `blob.NewStorage`. For SFTP backends with `externalSSH: true`, that path constructs a process command line by splitting `sshArguments` on spaces and passes the result directly to `exec.CommandContext(&amp;#34;ssh&amp;#34;)`. An `-oProxyCommand=&amp;lt;cmd&amp;gt;` token in `sshArguments` causes OpenSSH to invoke `&amp;lt;cmd&amp;gt;` via `$SHELL -c` before any TCP connection is attempted, giving the requester arbitrary command execution as the Kopia process user.&lt;/p&gt;
&lt;p&gt;## Analysis&lt;/p&gt;
&lt;p&gt;[`internal/server/server_authz_checks.go` lines 61–73](https://github.com/kopia/kopia/blob/v0.22.3/internal/server/server_authz_checks.go#L61-L73):&lt;/p&gt;
&lt;p&gt;when the server is started without `--server-username` or `--server-password`, `getAuthenticator()` returns `nil` and `requireUIUser` unconditionally authorizes the request. Every endpoint registered through `handleUIPossiblyNotConnected` becomes accessible without credentials.&lt;/p&gt;
&lt;p&gt;[`repo/blob/sftp/sftp_storage.go` lines 448–468](https://github.com/kopia/kopia/blob/v0.22.3/repo/blob/sftp/sftp_storage.go#L448-L468):&lt;/p&gt;
&lt;p&gt;`opt.SSHArguments` is populated from the JSON request body (`storage.config.sshArguments`). The string is split only on the literal ASCII space character, there is no shell style tokenizer, no quote handling, and no allowlist. Whatever tokens the caller supplies are appended to the `ssh` argv.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/kopia/kopia&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Kopia&amp;#39;s HTTP server, when started with `--without-password `, accepts unauthenticated requests to `/api/v1/repo/exists`. The handler forwards an attacker-supplied storage configuration to `blob.NewStorage`. For SFTP backends with `externalSSH: true`, that path constructs a process command line by splitting `sshArguments` on spaces and passes the result directly to `exec.CommandContext(&amp;#34;ssh&amp;#34;)`. An `-oProxyCommand=&amp;lt;cmd&amp;gt;` token in `sshArguments` causes OpenSSH to invoke `&amp;lt;cmd&amp;gt;` via `$SHELL -c` before any TCP connection is attempted, giving the requester arbitrary command execution as the Kopia process user.&lt;/p&gt;
&lt;p&gt;## Analysis&lt;/p&gt;
&lt;p&gt;[`internal/server/server_authz_checks.go` lines 61–73](https://github.com/kopia/kopia/blob/v0.22.3/internal/server/server_authz_checks.go#L61-L73):&lt;/p&gt;
&lt;p&gt;when the server is started without `--server-username` or `--server-password`, `getAuthenticator()` returns `nil` and `requireUIUser` unconditionally authorizes the request. Every endpoint registered through `handleUIPossiblyNotConnected` becomes accessible without credentials.&lt;/p&gt;
&lt;p&gt;[`repo/blob/sftp/sftp_storage.go` lines 448–468](https://github.com/kopia/kopia/blob/v0.22.3/repo/blob/sftp/sftp_storage.go#L448-L468):&lt;/p&gt;
&lt;p&gt;`opt.SSHArguments` is populated from the JSON request body (`storage.config.sshArguments`). The string is split only on the literal ASCII space character, there is no shell style tokenizer, no quote handling, and no allowlist. Whatever tokens the caller supplies are appended to the `ssh` argv.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2q4c-3mrw-63c3</guid>
    </item>
  </channel>
</rss>
