<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 00:45:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-358368</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358368</link>
      <description>EUVD-2026-358368</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358368</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53541</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53541</link>
      <description>&lt;p&gt;OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action&amp;#39;s configuration. However, prior to commit ebffd9f040f791208aee1db2e5a8aecd1e3e603d, a special case allows any argument whose name starts with `ot_` to bypass this filter. While two system arguments (`ot_executionTrackingId` and `ot_username`) are injected by OliveTin and overridden, all other `ot_`-prefixed arguments supplied by the user pass through unmodified. These bypassed arguments are not type-checked — the validation loop only iterates over the action&amp;#39;s defined arguments, so `ot_`-prefixed arguments skip all type safety checks entirely; set as environment variables — via `buildEnv()`, with completely unvalidated values, and passed to the executed command; and included in the template context — available as `.Arguments.ot_*` in template rendering. Commit ebffd9f040f791208aee1db2e5a8aecd1e3e603d contains a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action&amp;#39;s configuration. However, prior to commit ebffd9f040f791208aee1db2e5a8aecd1e3e603d, a special case allows any argument whose name starts with `ot_` to bypass this filter. While two system arguments (`ot_executionTrackingId` and `ot_username`) are injected by OliveTin and overridden, all other `ot_`-prefixed arguments supplied by the user pass through unmodified. These bypassed arguments are not type-checked — the validation loop only iterates over the action&amp;#39;s defined arguments, so `ot_`-prefixed arguments skip all type safety checks entirely; set as environment variables — via `buildEnv()`, with completely unvalidated values, and passed to the executed command; and included in the template context — available as `.Arguments.ot_*` in template rendering. Commit ebffd9f040f791208aee1db2e5a8aecd1e3e603d contains a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53541</guid>
    </item>
    <item>
      <title>GHSA-prj9-97mp-mwh2 — OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-prj9-97mp-mwh2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/OliveTin/OliveTin&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action&amp;#39;s configuration. However, a special case allows any argument whose name starts with `ot_` to bypass this filter. While two system arguments (`ot_executionTrackingId` and `ot_username`) are injected by OliveTin and overridden, all other `ot_`-prefixed arguments supplied by the user pass through unmodified.&lt;/p&gt;
&lt;p&gt;These bypassed arguments are:&lt;/p&gt;
&lt;p&gt;1. **Not type-checked** — the validation loop only iterates over the action&amp;#39;s defined arguments, so `ot_`-prefixed arguments skip all type safety checks entirely.
2. **Set as environment variables** — via `buildEnv()`, with completely unvalidated values, and passed to the executed command.
3. **Included in the template context** — available as `.Arguments.ot_*` in template rendering.&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;**Filter bypass — `service/internal/executor/executor.go` (lines 728–731):**&lt;/p&gt;
&lt;p&gt;```go
func keepArgument(name string, definedNames map[string]struct{}) bool {
    _, ok := definedNames[name]
    return ok || strings.HasPrefix(name, &amp;#34;ot_&amp;#34;)
}
```&lt;/p&gt;
&lt;p&gt;**System args only override two keys — `service/internal/executor/executor.go` (lines 742–745):**&lt;/p&gt;
&lt;p&gt;```go
func injectSystemArgs(req *ExecutionRequest) {
    req.Arguments[&amp;#34;ot_executionTrackingId&amp;#34;] = req.TrackingID
    req.Arguments[&amp;#34;ot_username&amp;#34;] = req.AuthenticatedUser.Username
}
```&lt;/p&gt;
&lt;p&gt;Any other `ot_`-prefixed argument (e.g., `ot_malicious`) survives both fu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/OliveTin/OliveTin&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action&amp;#39;s configuration. However, a special case allows any argument whose name starts with `ot_` to bypass this filter. While two system arguments (`ot_executionTrackingId` and `ot_username`) are injected by OliveTin and overridden, all other `ot_`-prefixed arguments supplied by the user pass through unmodified.&lt;/p&gt;
&lt;p&gt;These bypassed arguments are:&lt;/p&gt;
&lt;p&gt;1. **Not type-checked** — the validation loop only iterates over the action&amp;#39;s defined arguments, so `ot_`-prefixed arguments skip all type safety checks entirely.
2. **Set as environment variables** — via `buildEnv()`, with completely unvalidated values, and passed to the executed command.
3. **Included in the template context** — available as `.Arguments.ot_*` in template rendering.&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;**Filter bypass — `service/internal/executor/executor.go` (lines 728–731):**&lt;/p&gt;
&lt;p&gt;```go
func keepArgument(name string, definedNames map[string]struct{}) bool {
    _, ok := definedNames[name]
    return ok || strings.HasPrefix(name, &amp;#34;ot_&amp;#34;)
}
```&lt;/p&gt;
&lt;p&gt;**System args only override two keys — `service/internal/executor/executor.go` (lines 742–745):**&lt;/p&gt;
&lt;p&gt;```go
func injectSystemArgs(req *ExecutionRequest) {
    req.Arguments[&amp;#34;ot_executionTrackingId&amp;#34;] = req.TrackingID
    req.Arguments[&amp;#34;ot_username&amp;#34;] = req.AuthenticatedUser.Username
}
```&lt;/p&gt;
&lt;p&gt;Any other `ot_`-prefixed argument (e.g., `ot_malicious`) survives both fu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-prj9-97mp-mwh2</guid>
    </item>
  </channel>
</rss>
