<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 11:44:50 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292626</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292626</link>
      <description>EUVD-2026-292626</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292626</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41057</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41057</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two separate code paths still reflect arbitrary `Origin` headers with credentials allowed for all `/api/*` endpoints: (1) `plugin/API/router.php` lines 4-8 unconditionally reflect any origin before application code runs, and (2) `allowOrigin(true)` called by `get.json.php` and `set.json.php` reflects any origin with `Access-Control-Allow-Credentials: true`. An attacker can make cross-origin credentialed requests to any API endpoint and read authenticated responses containing user PII, email, admin status, and session-sensitive data. Commit 5e2b897ccac61eb6daca2dee4a6be3c4c2d93e13 contains a fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two separate code paths still reflect arbitrary `Origin` headers with credentials allowed for all `/api/*` endpoints: (1) `plugin/API/router.php` lines 4-8 unconditionally reflect any origin before application code runs, and (2) `allowOrigin(true)` called by `get.json.php` and `set.json.php` reflects any origin with `Access-Control-Allow-Credentials: true`. An attacker can make cross-origin credentialed requests to any API endpoint and read authenticated responses containing user PII, email, admin status, and session-sensitive data. Commit 5e2b897ccac61eb6daca2dee4a6be3c4c2d93e13 contains a fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41057</guid>
    </item>
    <item>
      <title>GHSA-ff5q-cc22-fgp4 — WWBN AVideo has a CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) Exposes Authenticated A…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ff5q-cc22-fgp4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The CORS origin validation fix in commit `986e64aad` is incomplete. Two separate code paths still reflect arbitrary `Origin` headers with credentials allowed for all `/api/*` endpoints: (1) `plugin/API/router.php` lines 4-8 unconditionally reflect any origin before application code runs, and (2) `allowOrigin(true)` called by `get.json.php` and `set.json.php` reflects any origin with `Access-Control-Allow-Credentials: true`. An attacker can make cross-origin credentialed requests to any API endpoint and read authenticated responses containing user PII, email, admin status, and session-sensitive data.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Bypass Vector 1: router.php independent CORS handler&lt;/p&gt;
&lt;p&gt;`plugin/API/router.php:4-8` runs before any application code:&lt;/p&gt;
&lt;p&gt;```php
// plugin/API/router.php lines 4-8
$HTTP_ORIGIN = empty($_SERVER[&amp;#39;HTTP_ORIGIN&amp;#39;]) ? @$_SERVER[&amp;#39;HTTP_REFERER&amp;#39;] : $_SERVER[&amp;#39;HTTP_ORIGIN&amp;#39;];
if (empty($HTTP_ORIGIN)) {
    header(&amp;#39;Access-Control-Allow-Origin: *&amp;#39;);
} else {
    header(&amp;#34;Access-Control-Allow-Origin: &amp;#34; . $HTTP_ORIGIN);
}
```&lt;/p&gt;
&lt;p&gt;This reflects **any** `Origin` header verbatim. For OPTIONS preflight requests (lines 14-18), the script exits immediately — the fixed `allowOrigin()` function never executes:&lt;/p&gt;
&lt;p&gt;```php
// plugin/API/router.php lines 14-18
if ($_SERVER[&amp;#39;REQUEST_METHOD&amp;#39;] === &amp;#39;OPTIONS&amp;#39;) {
    header(&amp;#34;Access-Control-Max-Age: 86400&amp;#34;);
    http_response_code(200);
    exit;
}
```&lt;/p&gt;
&lt;p&gt;All `/api/*` requests are routed through this file via `.htaccess` rules (lines 131-132).&lt;/p&gt;
&lt;p&gt;###…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The CORS origin validation fix in commit `986e64aad` is incomplete. Two separate code paths still reflect arbitrary `Origin` headers with credentials allowed for all `/api/*` endpoints: (1) `plugin/API/router.php` lines 4-8 unconditionally reflect any origin before application code runs, and (2) `allowOrigin(true)` called by `get.json.php` and `set.json.php` reflects any origin with `Access-Control-Allow-Credentials: true`. An attacker can make cross-origin credentialed requests to any API endpoint and read authenticated responses containing user PII, email, admin status, and session-sensitive data.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Bypass Vector 1: router.php independent CORS handler&lt;/p&gt;
&lt;p&gt;`plugin/API/router.php:4-8` runs before any application code:&lt;/p&gt;
&lt;p&gt;```php
// plugin/API/router.php lines 4-8
$HTTP_ORIGIN = empty($_SERVER[&amp;#39;HTTP_ORIGIN&amp;#39;]) ? @$_SERVER[&amp;#39;HTTP_REFERER&amp;#39;] : $_SERVER[&amp;#39;HTTP_ORIGIN&amp;#39;];
if (empty($HTTP_ORIGIN)) {
    header(&amp;#39;Access-Control-Allow-Origin: *&amp;#39;);
} else {
    header(&amp;#34;Access-Control-Allow-Origin: &amp;#34; . $HTTP_ORIGIN);
}
```&lt;/p&gt;
&lt;p&gt;This reflects **any** `Origin` header verbatim. For OPTIONS preflight requests (lines 14-18), the script exits immediately — the fixed `allowOrigin()` function never executes:&lt;/p&gt;
&lt;p&gt;```php
// plugin/API/router.php lines 14-18
if ($_SERVER[&amp;#39;REQUEST_METHOD&amp;#39;] === &amp;#39;OPTIONS&amp;#39;) {
    header(&amp;#34;Access-Control-Max-Age: 86400&amp;#34;);
    http_response_code(200);
    exit;
}
```&lt;/p&gt;
&lt;p&gt;All `/api/*` requests are routed through this file via `.htaccess` rules (lines 131-132).&lt;/p&gt;
&lt;p&gt;###…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ff5q-cc22-fgp4</guid>
    </item>
  </channel>
</rss>
