<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 00:25:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-264789</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264789</link>
      <description>EUVD-2026-264789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264789</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68619</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68619</link>
      <description>&lt;p&gt;Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages through a REST API endpoint. While the endpoint validates that the package name exists in the npm registry as a known plugin or webapp, the version parameter accepts arbitrary npm version specifiers including URLs. npm supports installing packages from git repositories, GitHub shorthand syntax, and HTTP/HTTPS URLs pointing to tarballs. When npm installs a package, it can automatically execute any `postinstall` script defined in `package.json`, enabling arbitrary code execution. The vulnerability exists because npm&amp;#39;s version specifier syntax is extremely flexible, and the SignalK code passes the version parameter directly to npm without sanitization. An attacker with admin access can install a package from an attacker-controlled source containing a malicious `postinstall` script. Version 2.19.0 contains a patch for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages through a REST API endpoint. While the endpoint validates that the package name exists in the npm registry as a known plugin or webapp, the version parameter accepts arbitrary npm version specifiers including URLs. npm supports installing packages from git repositories, GitHub shorthand syntax, and HTTP/HTTPS URLs pointing to tarballs. When npm installs a package, it can automatically execute any `postinstall` script defined in `package.json`, enabling arbitrary code execution. The vulnerability exists because npm&amp;#39;s version specifier syntax is extremely flexible, and the SignalK code passes the version parameter directly to npm without sanitization. An attacker with admin access can install a package from an attacker-controlled source containing a malicious `postinstall` script. Version 2.19.0 contains a patch for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68619</guid>
    </item>
    <item>
      <title>GHSA-93jc-vqqc-vvvh — Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-93jc-vqqc-vvvh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: signalk-server&lt;/p&gt;
&lt;p&gt;The SignalK appstore interface allows administrators to install npm packages through a REST API endpoint. While the endpoint validates that the package name exists in the npm registry as a known plugin or webapp, the version parameter accepts arbitrary npm version specifiers including URLs. npm supports installing packages from git repositories, GitHub shorthand syntax, and HTTP/HTTPS URLs pointing to tarballs. When npm installs a package, it can automatically execute any `postinstall` script defined in `package.json`, enabling arbitrary code execution.&lt;/p&gt;
&lt;p&gt;The vulnerability exists because npm&amp;#39;s version specifier syntax is extremely flexible, and the SignalK code passes the version parameter directly to npm without sanitization. An attacker with admin access can install a package from an attacker-controlled source containing a malicious `postinstall` script.&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;**File**: `src/interfaces/appstore.js` (lines 46-76)&lt;/p&gt;
&lt;p&gt;```javascript
app.post(
  [
    `${SERVERROUTESPREFIX}/appstore/install/:name/:version`,
    `${SERVERROUTESPREFIX}/appstore/install/:org/:name/:version`
  ],
  (req, res) =&amp;gt; {
    let name = req.params.name
    const version = req.params.version  // No validation on version format
    
    // ... validation only checks if package name exists ...
    
    installSKModule(name, version)  // Passes unsanitized version to npm
  }
)
```&lt;/p&gt;
&lt;p&gt;**File**: `src/modules.ts` (lines 180-205)&lt;/p&gt;
&lt;p&gt;```typescript
if (name) {
  packageString = version ? `${name}@${version}`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: signalk-server&lt;/p&gt;
&lt;p&gt;The SignalK appstore interface allows administrators to install npm packages through a REST API endpoint. While the endpoint validates that the package name exists in the npm registry as a known plugin or webapp, the version parameter accepts arbitrary npm version specifiers including URLs. npm supports installing packages from git repositories, GitHub shorthand syntax, and HTTP/HTTPS URLs pointing to tarballs. When npm installs a package, it can automatically execute any `postinstall` script defined in `package.json`, enabling arbitrary code execution.&lt;/p&gt;
&lt;p&gt;The vulnerability exists because npm&amp;#39;s version specifier syntax is extremely flexible, and the SignalK code passes the version parameter directly to npm without sanitization. An attacker with admin access can install a package from an attacker-controlled source containing a malicious `postinstall` script.&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;**File**: `src/interfaces/appstore.js` (lines 46-76)&lt;/p&gt;
&lt;p&gt;```javascript
app.post(
  [
    `${SERVERROUTESPREFIX}/appstore/install/:name/:version`,
    `${SERVERROUTESPREFIX}/appstore/install/:org/:name/:version`
  ],
  (req, res) =&amp;gt; {
    let name = req.params.name
    const version = req.params.version  // No validation on version format
    
    // ... validation only checks if package name exists ...
    
    installSKModule(name, version)  // Passes unsanitized version to npm
  }
)
```&lt;/p&gt;
&lt;p&gt;**File**: `src/modules.ts` (lines 180-205)&lt;/p&gt;
&lt;p&gt;```typescript
if (name) {
  packageString = version ? `${name}@${version}`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-93jc-vqqc-vvvh</guid>
    </item>
  </channel>
</rss>
