<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 12:26:56 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292133</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292133</link>
      <description>EUVD-2026-292133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292133</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40488</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40488</link>
      <description>&lt;p&gt;Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the product custom option file upload in OpenMage LTS uses an incomplete blocklist (`forbidden_extensions = php,exe`) to prevent dangerous file uploads. This blocklist can be trivially bypassed by using alternative PHP-executable extensions such as `.phtml`, `.phar`, `.php3`, `.php4`, `.php5`, `.php7`, and `.pht`. Files are stored in the publicly accessible `media/custom_options/quote/` directory, which lacks server-side execution restrictions for some configurations, enabling Remote Code Execution if this directory is not explicitly denied script execution. Version 20.17.0 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the product custom option file upload in OpenMage LTS uses an incomplete blocklist (`forbidden_extensions = php,exe`) to prevent dangerous file uploads. This blocklist can be trivially bypassed by using alternative PHP-executable extensions such as `.phtml`, `.phar`, `.php3`, `.php4`, `.php5`, `.php7`, and `.pht`. Files are stored in the publicly accessible `media/custom_options/quote/` directory, which lacks server-side execution restrictions for some configurations, enabling Remote Code Execution if this directory is not explicitly denied script execution. Version 20.17.0 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40488</guid>
    </item>
    <item>
      <title>GHSA-3j5q-7q7h-2hhv — OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3j5q-7q7h-2hhv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: openmage/magento-lts&lt;/p&gt;
&lt;p&gt;The product custom option file upload in OpenMage LTS uses an incomplete blocklist (`forbidden_extensions = php,exe`) to prevent dangerous file uploads. This blocklist can be trivially bypassed by using alternative PHP-executable extensions such as `.phtml`, `.phar`, `.php3`, `.php4`, `.php5`, `.php7`, and `.pht`. Files are stored in the publicly accessible `media/custom_options/quote/` directory, which lacks server-side execution restrictions for some configurations, enabling Remote Code Execution if this directory is not explicitly denied script execution.&lt;/p&gt;
&lt;p&gt;## Affected Version&lt;/p&gt;
&lt;p&gt;- **Project:** OpenMage/magento-lts
- **Vulnerable File:** `https://github.com/OpenMage/magento-lts/blob/main/app/code/core/Mage/Catalog/Model/Product/Option/Type/File.php`
- **Vulnerable Lines:** 230-237 (`_validateUploadedFile()`)
- **Configuration:** `app/code/core/Mage/Catalog/etc/config.xml:824`&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;The file upload handler uses `Zend_File_Transfer_Adapter_Http` directly with `ExcludeExtension` validator, referencing only:&lt;/p&gt;
&lt;p&gt;```xml
&amp;lt;!-- Catalog/etc/config.xml:824 --&amp;gt;
&amp;lt;forbidden_extensions&amp;gt;php,exe&amp;lt;/forbidden_extensions&amp;gt;
```&lt;/p&gt;
&lt;p&gt;This misses the comprehensive `protected_extensions` blocklist defined elsewhere:&lt;/p&gt;
&lt;p&gt;```xml
&amp;lt;!-- Core/etc/config.xml:449-478 --&amp;gt;
php, php3, php4, php5, php7, htaccess, jsp, pl, py, asp, sh, cgi, 
htm, html, pht, phtml, shtml
```&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;```php
// app/code/core/Mage/Catalog/Model/Product/Option/Type/File.php:230-237
$_allowed = $this-&amp;gt;_parseExtensionsStri…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: openmage/magento-lts&lt;/p&gt;
&lt;p&gt;The product custom option file upload in OpenMage LTS uses an incomplete blocklist (`forbidden_extensions = php,exe`) to prevent dangerous file uploads. This blocklist can be trivially bypassed by using alternative PHP-executable extensions such as `.phtml`, `.phar`, `.php3`, `.php4`, `.php5`, `.php7`, and `.pht`. Files are stored in the publicly accessible `media/custom_options/quote/` directory, which lacks server-side execution restrictions for some configurations, enabling Remote Code Execution if this directory is not explicitly denied script execution.&lt;/p&gt;
&lt;p&gt;## Affected Version&lt;/p&gt;
&lt;p&gt;- **Project:** OpenMage/magento-lts
- **Vulnerable File:** `https://github.com/OpenMage/magento-lts/blob/main/app/code/core/Mage/Catalog/Model/Product/Option/Type/File.php`
- **Vulnerable Lines:** 230-237 (`_validateUploadedFile()`)
- **Configuration:** `app/code/core/Mage/Catalog/etc/config.xml:824`&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;The file upload handler uses `Zend_File_Transfer_Adapter_Http` directly with `ExcludeExtension` validator, referencing only:&lt;/p&gt;
&lt;p&gt;```xml
&amp;lt;!-- Catalog/etc/config.xml:824 --&amp;gt;
&amp;lt;forbidden_extensions&amp;gt;php,exe&amp;lt;/forbidden_extensions&amp;gt;
```&lt;/p&gt;
&lt;p&gt;This misses the comprehensive `protected_extensions` blocklist defined elsewhere:&lt;/p&gt;
&lt;p&gt;```xml
&amp;lt;!-- Core/etc/config.xml:449-478 --&amp;gt;
php, php3, php4, php5, php7, htaccess, jsp, pl, py, asp, sh, cgi, 
htm, html, pht, phtml, shtml
```&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;```php
// app/code/core/Mage/Catalog/Model/Product/Option/Type/File.php:230-237
$_allowed = $this-&amp;gt;_parseExtensionsStri…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3j5q-7q7h-2hhv</guid>
    </item>
  </channel>
</rss>
