<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:53:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-222299</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-222299</link>
      <description>EUVD-2026-222299</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-222299</guid>
    </item>
    <item>
      <title>fkie_cve-2024-47170</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47170</link>
      <description>&lt;p&gt;Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unauthorized access to sensitive information and exposure of confidential configuration files. This only affects installations with `JSON_STORAGE` enabled which is intended to local/self-hosting only. Version 1.0.330 fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unauthorized access to sensitive information and exposure of confidential configuration files. This only affects installations with `JSON_STORAGE` enabled which is intended to local/self-hosting only. Version 1.0.330 fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-47170</guid>
    </item>
    <item>
      <title>GHSA-h355-hm5h-cm8h — Agnai File Disclosure Vulnerability: JSON via Path Traversal</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h355-hm5h-cm8h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: agnai&lt;/p&gt;
&lt;p&gt;### CWE-35: Path Traversal&lt;/p&gt;
&lt;p&gt;https://cwe.mitre.org/data/definitions/35.html&lt;/p&gt;
&lt;p&gt;### CVSSv3.1 4.3 - Medium
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A vulnerability has been discovered in **Agnai** that permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unauthorized access to sensitive information and exposure of confidential configuration files.
**This only affects installations with `JSON_STORAGE` enabled which is intended to local/self-hosting only.**&lt;/p&gt;
&lt;p&gt;### Details &amp;amp; PoC&lt;/p&gt;
&lt;p&gt;This is a path traversal vulnerability. An attacker can exploit this vulnerability by sending a specially crafted request:&lt;/p&gt;
&lt;p&gt;```tsx
GET /api/json/messages/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%61%70%70%2fpackage HTTP/1.1
```&lt;/p&gt;
&lt;p&gt;In this example, the attacker retrieves the `package.json` file content from the server by manipulating the file path.&lt;/p&gt;
&lt;p&gt;The request is processed by the `loadMessages` handler in `agnai/srv/api/json/index.ts` and a file is read and returned to the client. The read filename is constructed using string interpolation, with no guard or check for path traversal: https://github.com/agnaistic/agnai/blob/2b878b7ca66471c5dd080197ad9ca2f7f0022655/srv/api/json/index.ts#L77&lt;/p&gt;
&lt;p&gt;#### Constraints&lt;/p&gt;
&lt;p&gt;Environment constraints: JSON Storage enabled (non standard)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This vulnerability is classified as a path traversal vulnerability. Specifically, any JSON file on…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: agnai&lt;/p&gt;
&lt;p&gt;### CWE-35: Path Traversal&lt;/p&gt;
&lt;p&gt;https://cwe.mitre.org/data/definitions/35.html&lt;/p&gt;
&lt;p&gt;### CVSSv3.1 4.3 - Medium
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A vulnerability has been discovered in **Agnai** that permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unauthorized access to sensitive information and exposure of confidential configuration files.
**This only affects installations with `JSON_STORAGE` enabled which is intended to local/self-hosting only.**&lt;/p&gt;
&lt;p&gt;### Details &amp;amp; PoC&lt;/p&gt;
&lt;p&gt;This is a path traversal vulnerability. An attacker can exploit this vulnerability by sending a specially crafted request:&lt;/p&gt;
&lt;p&gt;```tsx
GET /api/json/messages/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%61%70%70%2fpackage HTTP/1.1
```&lt;/p&gt;
&lt;p&gt;In this example, the attacker retrieves the `package.json` file content from the server by manipulating the file path.&lt;/p&gt;
&lt;p&gt;The request is processed by the `loadMessages` handler in `agnai/srv/api/json/index.ts` and a file is read and returned to the client. The read filename is constructed using string interpolation, with no guard or check for path traversal: https://github.com/agnaistic/agnai/blob/2b878b7ca66471c5dd080197ad9ca2f7f0022655/srv/api/json/index.ts#L77&lt;/p&gt;
&lt;p&gt;#### Constraints&lt;/p&gt;
&lt;p&gt;Environment constraints: JSON Storage enabled (non standard)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This vulnerability is classified as a path traversal vulnerability. Specifically, any JSON file on…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h355-hm5h-cm8h</guid>
    </item>
  </channel>
</rss>
