<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 13:42:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277139</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277139</link>
      <description>EUVD-2026-277139</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277139</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33513</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33513</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under the web root can be included. In our test this yielded confirmed file disclosure and code execution of existing PHP content (e.g., `view/about.php`), and it *can* escalate to RCE if an attacker can place or control a PHP file elsewhere in the tree. As of time of publication, no patched versions are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under the web root can be included. In our test this yielded confirmed file disclosure and code execution of existing PHP content (e.g., `view/about.php`), and it *can* escalate to RCE if an attacker can place or control a PHP file elsewhere in the tree. As of time of publication, no patched versions are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33513</guid>
    </item>
    <item>
      <title>GHSA-8fw8-q79c-fp9m — AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8fw8-q79c-fp9m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;### Summary
An unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under the web root can be included. In our test this yielded confirmed file disclosure and code execution of existing PHP content (e.g., `view/about.php`), and it *can* escalate to RCE if an attacker can place or control a PHP file elsewhere in the tree. 
### Details
- Entry point: `plugin/API/get.json.php` sets `$global[&amp;#39;bypassSameDomainCheck&amp;#39;]=1` and merges GET/POST/JSON into `$parameters` without authentication or API secret.
- Handler: `plugin/API/API.php`, method `get_api_locale()` (lines ~5009–5023):
  ```php
  $parameters[&amp;#39;language&amp;#39;] = strtolower($parameters[&amp;#39;language&amp;#39;]);
  $file = &amp;#34;{$global[&amp;#39;systemRootPath&amp;#39;]}locale/{$parameters[&amp;#39;language&amp;#39;]}.php&amp;#34;;
  if (!file_exists($file)) { return new ApiObject(&amp;#34;This language does not exists&amp;#34;); }
  include $file;
  ```
  No validation is performed; `../` traversal is accepted.
- Because `include` executes PHP, any reachable PHP file is executed in the web server context.&lt;/p&gt;
&lt;p&gt;### PoC
1. Fetch an arbitrary PHP file (no auth):
   ```
   GET /plugin/API/get.json.php?APIName=locale&amp;amp;language=../view/about HTTP/1.1
   Host: &amp;lt;target&amp;gt;
   ```
   Response returns the rendered About page HTML, proving traversal outside `locale/`.
2. RCE with an attacker PHP file (any writable PHP path):
   ```
   GET /plugin/API/get.json.php?APIName=locale&amp;amp;language=..…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;### Summary
An unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under the web root can be included. In our test this yielded confirmed file disclosure and code execution of existing PHP content (e.g., `view/about.php`), and it *can* escalate to RCE if an attacker can place or control a PHP file elsewhere in the tree. 
### Details
- Entry point: `plugin/API/get.json.php` sets `$global[&amp;#39;bypassSameDomainCheck&amp;#39;]=1` and merges GET/POST/JSON into `$parameters` without authentication or API secret.
- Handler: `plugin/API/API.php`, method `get_api_locale()` (lines ~5009–5023):
  ```php
  $parameters[&amp;#39;language&amp;#39;] = strtolower($parameters[&amp;#39;language&amp;#39;]);
  $file = &amp;#34;{$global[&amp;#39;systemRootPath&amp;#39;]}locale/{$parameters[&amp;#39;language&amp;#39;]}.php&amp;#34;;
  if (!file_exists($file)) { return new ApiObject(&amp;#34;This language does not exists&amp;#34;); }
  include $file;
  ```
  No validation is performed; `../` traversal is accepted.
- Because `include` executes PHP, any reachable PHP file is executed in the web server context.&lt;/p&gt;
&lt;p&gt;### PoC
1. Fetch an arbitrary PHP file (no auth):
   ```
   GET /plugin/API/get.json.php?APIName=locale&amp;amp;language=../view/about HTTP/1.1
   Host: &amp;lt;target&amp;gt;
   ```
   Response returns the rendered About page HTML, proving traversal outside `locale/`.
2. RCE with an attacker PHP file (any writable PHP path):
   ```
   GET /plugin/API/get.json.php?APIName=locale&amp;amp;language=..…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8fw8-q79c-fp9m</guid>
    </item>
  </channel>
</rss>
