<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 09:27:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-267139</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267139</link>
      <description>EUVD-2026-267139</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267139</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23515</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23515</link>
      <description>&lt;p&gt;Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated users can also exploit this vulnerability if security is disabled on the Signal K server. This occurs due to unsafe construction of shell commands when processing navigation.datetime values received via WebSocket delta messages. This vulnerability is fixed in 1.5.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated users can also exploit this vulnerability if security is disabled on the Signal K server. This occurs due to unsafe construction of shell commands when processing navigation.datetime values received via WebSocket delta messages. This vulnerability is fixed in 1.5.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23515</guid>
    </item>
    <item>
      <title>GHSA-p8gp-2w28-mhwg — Signal K set-system-time plugin vulnerable to RCE - Command Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p8gp-2w28-mhwg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @signalk/set-system-time&lt;/p&gt;
&lt;p&gt;### Summary
A Command Injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated users can also exploit this vulnerability if security is disabled on the Signal K server. This occurs due to unsafe construction of shell commands when processing `navigation.datetime` values received via WebSocket delta messages.&lt;/p&gt;
&lt;p&gt;### Details
**Product:** Signal K set-system-time plugin  
**Repository:** https://github.com/SignalK/set-system-time&lt;/p&gt;
&lt;p&gt;File: `index.js`, lines 60-71&lt;/p&gt;
&lt;p&gt;```javascript
      stream.onValue(function (datetime) {
        var child
        if (process.platform == &amp;#39;win32&amp;#39;) {
          console.error(&amp;#34;Set-system-time supports only linux-like os&amp;#39;s&amp;#34;)
        } else {
          if( ! plugin.useNetworkTime(options) ){
            const useSudo = typeof options.sudo === &amp;#39;undefined&amp;#39; || options.sudo
            const setDate = `date --iso-8601 -u -s &amp;#34;${datetime}&amp;#34;`  // ← VULNERABLE
            const command = useSudo
              ? `if sudo -n date &amp;amp;&amp;gt; /dev/null ; then sudo ${setDate} ; else exit 3 ; fi`
              : setDate
            child = require(&amp;#39;child_process&amp;#39;).spawn(&amp;#39;sh&amp;#39;, [&amp;#39;-c&amp;#39;, command])  // ← EXECUTES SHELL
```&lt;/p&gt;
&lt;p&gt;The vulnerability has three components:&lt;/p&gt;
&lt;p&gt;1. **Unsanitized Input**: The `datetime` value from `navigation.datetime` Signal K path is directly interpolated into a shell command without validation
2. **Shell Execution**: The command…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @signalk/set-system-time&lt;/p&gt;
&lt;p&gt;### Summary
A Command Injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated users can also exploit this vulnerability if security is disabled on the Signal K server. This occurs due to unsafe construction of shell commands when processing `navigation.datetime` values received via WebSocket delta messages.&lt;/p&gt;
&lt;p&gt;### Details
**Product:** Signal K set-system-time plugin  
**Repository:** https://github.com/SignalK/set-system-time&lt;/p&gt;
&lt;p&gt;File: `index.js`, lines 60-71&lt;/p&gt;
&lt;p&gt;```javascript
      stream.onValue(function (datetime) {
        var child
        if (process.platform == &amp;#39;win32&amp;#39;) {
          console.error(&amp;#34;Set-system-time supports only linux-like os&amp;#39;s&amp;#34;)
        } else {
          if( ! plugin.useNetworkTime(options) ){
            const useSudo = typeof options.sudo === &amp;#39;undefined&amp;#39; || options.sudo
            const setDate = `date --iso-8601 -u -s &amp;#34;${datetime}&amp;#34;`  // ← VULNERABLE
            const command = useSudo
              ? `if sudo -n date &amp;amp;&amp;gt; /dev/null ; then sudo ${setDate} ; else exit 3 ; fi`
              : setDate
            child = require(&amp;#39;child_process&amp;#39;).spawn(&amp;#39;sh&amp;#39;, [&amp;#39;-c&amp;#39;, command])  // ← EXECUTES SHELL
```&lt;/p&gt;
&lt;p&gt;The vulnerability has three components:&lt;/p&gt;
&lt;p&gt;1. **Unsanitized Input**: The `datetime` value from `navigation.datetime` Signal K path is directly interpolated into a shell command without validation
2. **Shell Execution**: The command…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p8gp-2w28-mhwg</guid>
    </item>
  </channel>
</rss>
