<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 04:54:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-280035</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280035</link>
      <description>EUVD-2026-280035</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280035</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35038</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35038</link>
      <description>&lt;p&gt;Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated user to bypass prototype boundary filtering to extract internal functions and properties from the global prototype object this violates data isolation and lets a user read more than they should. This issue has been patched in version 2.24.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated user to bypass prototype boundary filtering to extract internal functions and properties from the global prototype object this violates data isolation and lets a user read more than they should. This issue has been patched in version 2.24.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35038</guid>
    </item>
    <item>
      <title>GHSA-qh3j-mrg8-f234 — Signal K Server: Arbitrary Prototype Read via `from` Field Bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qh3j-mrg8-f234</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: signalk-server&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The /signalk/v1/applicationData/... JSON-patch endpoint allows users to modify stored application data. To prevent Prototype Pollution, the developers implemented an isPrototypePollutionPath guard. However, this guard only checks the path property of incoming JSON-patch objects. It completely fails to check the from property. Because JSON-patch operations like copy and move extract data using the from property path, an attacker can construct a payload where from targets /__proto__/someProperty, completely evading the security check and successfully executing an Arbitrary Prototype Read.&lt;/p&gt;
&lt;p&gt;While this does not allow arbitrary code execution (as the destination path remains protected from __proto__), it does allow a user to exfiltrate internal Node functions and prototype state into their own application data.&lt;/p&gt;
&lt;p&gt;## Vulnerability Root Cause&lt;/p&gt;
&lt;p&gt;File: src/interfaces/applicationData.js (Lines 48-57)
```
const DANGEROUS_PATH_SEGMENTS = [&amp;#39;__proto__&amp;#39;, &amp;#39;constructor&amp;#39;, &amp;#39;prototype&amp;#39;]&lt;/p&gt;
&lt;p&gt;function isPrototypePollutionPath(pathString) {
  const segments = pathString.split(/[./]/)
  return segments.some((seg) =&amp;gt; DANGEROUS_PATH_SEGMENTS.includes(seg))
}&lt;/p&gt;
&lt;p&gt;function hasPrototypePollutionPatch(patches) {
  return patches.some(
    // [!VULNERABLE] Only checks patch.path, completely ignores patch.from
    (patch) =&amp;gt; patch.path &amp;amp;&amp;amp; isPrototypePollutionPath(patch.path) 
  )
}
```
At Line 201:
```
if (hasPrototypePollutionPatch(req.body)) {
  res.status(400).send(&amp;#39;invalid patch path&amp;#39;)
  return
}…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: signalk-server&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The /signalk/v1/applicationData/... JSON-patch endpoint allows users to modify stored application data. To prevent Prototype Pollution, the developers implemented an isPrototypePollutionPath guard. However, this guard only checks the path property of incoming JSON-patch objects. It completely fails to check the from property. Because JSON-patch operations like copy and move extract data using the from property path, an attacker can construct a payload where from targets /__proto__/someProperty, completely evading the security check and successfully executing an Arbitrary Prototype Read.&lt;/p&gt;
&lt;p&gt;While this does not allow arbitrary code execution (as the destination path remains protected from __proto__), it does allow a user to exfiltrate internal Node functions and prototype state into their own application data.&lt;/p&gt;
&lt;p&gt;## Vulnerability Root Cause&lt;/p&gt;
&lt;p&gt;File: src/interfaces/applicationData.js (Lines 48-57)
```
const DANGEROUS_PATH_SEGMENTS = [&amp;#39;__proto__&amp;#39;, &amp;#39;constructor&amp;#39;, &amp;#39;prototype&amp;#39;]&lt;/p&gt;
&lt;p&gt;function isPrototypePollutionPath(pathString) {
  const segments = pathString.split(/[./]/)
  return segments.some((seg) =&amp;gt; DANGEROUS_PATH_SEGMENTS.includes(seg))
}&lt;/p&gt;
&lt;p&gt;function hasPrototypePollutionPatch(patches) {
  return patches.some(
    // [!VULNERABLE] Only checks patch.path, completely ignores patch.from
    (patch) =&amp;gt; patch.path &amp;amp;&amp;amp; isPrototypePollutionPath(patch.path) 
  )
}
```
At Line 201:
```
if (hasPrototypePollutionPatch(req.body)) {
  res.status(400).send(&amp;#39;invalid patch path&amp;#39;)
  return
}…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qh3j-mrg8-f234</guid>
    </item>
  </channel>
</rss>
