<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 22:35:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-264911</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264911</link>
      <description>EUVD-2026-264911</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264911</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66398</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66398</link>
      <description>&lt;p&gt;Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator&amp;#39;s &amp;#34;Restore&amp;#34; functionality to overwrite critical server configuration files (e.g., `security.json`, `package.json`), leading to account takeover and Remote Code Execution (RCE). Version 2.19.0 patches this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator&amp;#39;s &amp;#34;Restore&amp;#34; functionality to overwrite critical server configuration files (e.g., `security.json`, `package.json`), leading to account takeover and Remote Code Execution (RCE). Version 2.19.0 patches this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66398</guid>
    </item>
    <item>
      <title>GHSA-w3x5-7c4c-66p9 — Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w3x5-7c4c-66p9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: signalk-server&lt;/p&gt;
&lt;p&gt;### Summary
An unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator&amp;#39;s &amp;#34;Restore&amp;#34; functionality to overwrite critical server configuration files (e.g., `security.json`, `package.json`), leading to account takeover and Remote Code Execution (RCE).&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability is caused by the use of a module-level global variable `restoreFilePath` in `src/serverroutes.ts`, which is shared across all requests.&lt;/p&gt;
&lt;p&gt;**Vulnerable Code Analysis:**
1.  **Global State**: `restoreFilePath` is defined at the top level of the module.
    ```typescript
    // src/serverroutes.ts
    let restoreFilePath: string
    ```
2.  **Unauthenticated State Pollution**: The `/skServer/validateBackup` endpoint updates this variable. Crucially, this endpoint **lacks authentication middleware**, allowing any user to access it.
    ```typescript
    app.post(`${SERVERROUTESPREFIX}/validateBackup`, (req, res) =&amp;gt; {
      // ... handles file upload ...
      restoreFilePath = fs.mkdtempSync(...) // Attacker controls this path
    })
    ```
3.  **Restore Hijacking**: The `/skServer/restore` endpoint uses the polluted `restoreFilePath` to perform the restoration.
    ```typescript
    app.post(`${SERVERROUTESPREFIX}/restore`, (req, res) =&amp;gt; {
      // ...
      const unzipStream = unzipper.Extract({ path: restoreFilePath }) // Uses polluted path
      // ...
    })
    ```&lt;/p&gt;
&lt;p&gt;**E…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: signalk-server&lt;/p&gt;
&lt;p&gt;### Summary
An unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator&amp;#39;s &amp;#34;Restore&amp;#34; functionality to overwrite critical server configuration files (e.g., `security.json`, `package.json`), leading to account takeover and Remote Code Execution (RCE).&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability is caused by the use of a module-level global variable `restoreFilePath` in `src/serverroutes.ts`, which is shared across all requests.&lt;/p&gt;
&lt;p&gt;**Vulnerable Code Analysis:**
1.  **Global State**: `restoreFilePath` is defined at the top level of the module.
    ```typescript
    // src/serverroutes.ts
    let restoreFilePath: string
    ```
2.  **Unauthenticated State Pollution**: The `/skServer/validateBackup` endpoint updates this variable. Crucially, this endpoint **lacks authentication middleware**, allowing any user to access it.
    ```typescript
    app.post(`${SERVERROUTESPREFIX}/validateBackup`, (req, res) =&amp;gt; {
      // ... handles file upload ...
      restoreFilePath = fs.mkdtempSync(...) // Attacker controls this path
    })
    ```
3.  **Restore Hijacking**: The `/skServer/restore` endpoint uses the polluted `restoreFilePath` to perform the restoration.
    ```typescript
    app.post(`${SERVERROUTESPREFIX}/restore`, (req, res) =&amp;gt; {
      // ...
      const unzipStream = unzipper.Extract({ path: restoreFilePath }) // Uses polluted path
      // ...
    })
    ```&lt;/p&gt;
&lt;p&gt;**E…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w3x5-7c4c-66p9</guid>
    </item>
  </channel>
</rss>
