<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:14:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-261426</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261426</link>
      <description>EUVD-2026-261426</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261426</guid>
    </item>
    <item>
      <title>fkie_cve-2025-65025</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65025</link>
      <description>&lt;p&gt;esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path traversal during NPM package tarball extraction. An attacker can craft a malicious NPM package containing specially crafted file paths (e.g., package/../../tmp/evil.js). When esm.sh downloads and extracts this package, files may be written to arbitrary locations on the server, escaping the intended extraction directory. This issue has been patched in version 136.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path traversal during NPM package tarball extraction. An attacker can craft a malicious NPM package containing specially crafted file paths (e.g., package/../../tmp/evil.js). When esm.sh downloads and extracts this package, files may be written to arbitrary locations on the server, escaping the intended extraction directory. This issue has been patched in version 136.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-65025</guid>
    </item>
    <item>
      <title>GHSA-h3mw-4f23-gwpw — esm.sh CDN service has arbitrary file write via tarslip</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h3mw-4f23-gwpw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/esm-dev/esm.sh&lt;/p&gt;
&lt;p&gt;### Summary
The esm.sh CDN service is vulnerable to a Path Traversal (CWE-22) vulnerability during NPM package tarball extraction.  
An attacker can craft a malicious NPM package containing specially crafted file paths (e.g., `package/../../tmp/evil.js`).  
When esm.sh downloads and extracts this package, files may be written to arbitrary locations on the server, escaping the intended extraction directory.&lt;/p&gt;
&lt;p&gt;Uploading files containing `../` in the path is not allowed on official registries (npm, GitHub), but the `X-Npmrc` header allows specifying any arbitrary registry.  
By setting the registry to an attacker-controlled server via the `X-Npmrc` header, this vulnerability can be triggered.&lt;/p&gt;
&lt;p&gt;### Details
**file:** `server/npmrc.go`  
**line:** 552-567&lt;/p&gt;
&lt;p&gt;```go
func extractPackageTarball(installDir string, pkgName string, tarball io.Reader) (err error) {
    
    pkgDir := path.Join(installDir, &amp;#34;node_modules&amp;#34;, pkgName)
    
    tr := tar.NewReader(unziped)
    for {
        h, err := tr.Next()
        // ...
        
        // Strip tarball root directory
        _, name := utils.SplitByFirstByte(h.Name, &amp;#39;/&amp;#39;)  // &amp;#34;package/../../tmp/evil&amp;#34; → &amp;#34;../../tmp/evil&amp;#34;
        filename := path.Join(pkgDir, name)             // ← No validation
        
        if h.Typeflag != tar.TypeReg {
            continue 
        }
        
        // Extension filtering
        extname := path.Ext(filename)
        if !(extname != &amp;#34;&amp;#34; &amp;amp;&amp;amp; (allowed_extensions)) {
            continue  // Only extract .js,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/esm-dev/esm.sh&lt;/p&gt;
&lt;p&gt;### Summary
The esm.sh CDN service is vulnerable to a Path Traversal (CWE-22) vulnerability during NPM package tarball extraction.  
An attacker can craft a malicious NPM package containing specially crafted file paths (e.g., `package/../../tmp/evil.js`).  
When esm.sh downloads and extracts this package, files may be written to arbitrary locations on the server, escaping the intended extraction directory.&lt;/p&gt;
&lt;p&gt;Uploading files containing `../` in the path is not allowed on official registries (npm, GitHub), but the `X-Npmrc` header allows specifying any arbitrary registry.  
By setting the registry to an attacker-controlled server via the `X-Npmrc` header, this vulnerability can be triggered.&lt;/p&gt;
&lt;p&gt;### Details
**file:** `server/npmrc.go`  
**line:** 552-567&lt;/p&gt;
&lt;p&gt;```go
func extractPackageTarball(installDir string, pkgName string, tarball io.Reader) (err error) {
    
    pkgDir := path.Join(installDir, &amp;#34;node_modules&amp;#34;, pkgName)
    
    tr := tar.NewReader(unziped)
    for {
        h, err := tr.Next()
        // ...
        
        // Strip tarball root directory
        _, name := utils.SplitByFirstByte(h.Name, &amp;#39;/&amp;#39;)  // &amp;#34;package/../../tmp/evil&amp;#34; → &amp;#34;../../tmp/evil&amp;#34;
        filename := path.Join(pkgDir, name)             // ← No validation
        
        if h.Typeflag != tar.TypeReg {
            continue 
        }
        
        // Extension filtering
        extname := path.Ext(filename)
        if !(extname != &amp;#34;&amp;#34; &amp;amp;&amp;amp; (allowed_extensions)) {
            continue  // Only extract .js,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h3mw-4f23-gwpw</guid>
    </item>
  </channel>
</rss>
