<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 13:19:50 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-267665</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267665</link>
      <description>EUVD-2026-267665</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267665</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25760</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25760</link>
      <description>&lt;p&gt;Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated path traversal / arbitrary file read issue, and it can expose credentials, configs, and keys. This vulnerability is fixed in 1.6.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated path traversal / arbitrary file read issue, and it can expose credentials, configs, and keys. This vulnerability is fixed in 1.6.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25760</guid>
    </item>
    <item>
      <title>GHSA-2286-hxv5-cmp2 — Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2286-hxv5-cmp2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/bishopfox/sliver&lt;/p&gt;
&lt;p&gt;## Summary
A Path Traversal vulnerability in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated **Path Traversal / arbitrary file read** issue, and it can expose credentials, configs, and keys.&lt;/p&gt;
&lt;p&gt;## Affected Component
- Website content management (gRPC): `WebsiteAddContent`, `Website`, `Websites`
- Server-side file read in `Website.ToProtobuf`&lt;/p&gt;
&lt;p&gt;## Impact
- **Arbitrary file read** as the Sliver server OS user.
- Exposure of sensitive data such as operator configs, TLS keys, tokens, and logs.&lt;/p&gt;
&lt;p&gt;## Root Cause
The server accepts and persists arbitrary website paths from the operator, then later reads from disk using that path without sanitization or containment.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code References
- `server/rpc/rpc-website.go:100` — accepts `content.Path` from operator RPC and persists it via `website.AddContent`
- `server/db/models/website.go:52` — reads from disk with `filepath.Join(webContentDir, webcontent.Path)` without validating or constraining `webcontent.Path`&lt;/p&gt;
&lt;p&gt;## Proof of Concept (PoC)&lt;/p&gt;
&lt;p&gt;### Steps (local test)
1. Build the server:
   ```bash
   go build -mod=vendor -tags go_sqlite,server -o sliver-server ./server
   ```
2. Create an operator config (permission `all` for website operations):
   ```bash
   ./sliver-server operator -n testop -l 127.0.0.1 -p 31337 -P all -o file -s /tmp
   ```
3. Start the daemon:
   ```bash
   ./sliver-server daemon -l 127.0.0.1 -p 31337
   ```
4. Run the PoC:
   `…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/bishopfox/sliver&lt;/p&gt;
&lt;p&gt;## Summary
A Path Traversal vulnerability in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated **Path Traversal / arbitrary file read** issue, and it can expose credentials, configs, and keys.&lt;/p&gt;
&lt;p&gt;## Affected Component
- Website content management (gRPC): `WebsiteAddContent`, `Website`, `Websites`
- Server-side file read in `Website.ToProtobuf`&lt;/p&gt;
&lt;p&gt;## Impact
- **Arbitrary file read** as the Sliver server OS user.
- Exposure of sensitive data such as operator configs, TLS keys, tokens, and logs.&lt;/p&gt;
&lt;p&gt;## Root Cause
The server accepts and persists arbitrary website paths from the operator, then later reads from disk using that path without sanitization or containment.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code References
- `server/rpc/rpc-website.go:100` — accepts `content.Path` from operator RPC and persists it via `website.AddContent`
- `server/db/models/website.go:52` — reads from disk with `filepath.Join(webContentDir, webcontent.Path)` without validating or constraining `webcontent.Path`&lt;/p&gt;
&lt;p&gt;## Proof of Concept (PoC)&lt;/p&gt;
&lt;p&gt;### Steps (local test)
1. Build the server:
   ```bash
   go build -mod=vendor -tags go_sqlite,server -o sliver-server ./server
   ```
2. Create an operator config (permission `all` for website operations):
   ```bash
   ./sliver-server operator -n testop -l 127.0.0.1 -p 31337 -P all -o file -s /tmp
   ```
3. Start the daemon:
   ```bash
   ./sliver-server daemon -l 127.0.0.1 -p 31337
   ```
4. Run the PoC:
   `…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2286-hxv5-cmp2</guid>
    </item>
  </channel>
</rss>
