<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 22:41:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-334008</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-334008</link>
      <description>EUVD-2026-334008</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-334008</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55668</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55668</link>
      <description>&lt;p&gt;File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the user&amp;#39;s scope. This issue is fixed in version 2.63.16.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the user&amp;#39;s scope. This issue is fixed in version 2.63.16.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55668</guid>
    </item>
    <item>
      <title>GHSA-8wc8-hf36-mjh9 — File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8wc8-hf36-mjh9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`ScopedFs` confines every File Browser user to a scope directory. Its `within()` guard is meant to reject any operation that follows a symbolic link out of that scope. When the link target does not exist yet, the guard walks up to the nearest existing ancestor and validates that instead. For a dangling symlink (target does not exist), the nearest existing ancestor is the in-scope directory containing the link, so the guard returns &amp;#34;in scope&amp;#34; and the subsequent `os.OpenFile(O_CREATE)` follows the link and creates the file at its out-of-scope target.&lt;/p&gt;
&lt;p&gt;A post-auth user with `Create` and `Modify` permission can write attacker-controlled content to any non-existent path outside their scope that the File Browser process can write to. The precondition is a dangling symlink present inside the user&amp;#39;s scope, which is the same out-of-band precondition the rest of `ScopedFs` is built to defend against.&lt;/p&gt;
&lt;p&gt;This is a patch-gap variant of the GHSA-239w-m3h6-ch8v symlink confinement issue, not a resubmission of the already-published vulnerable-version behavior: GHSA-239w-m3h6-ch8v marks `&amp;lt;= 2.63.13` vulnerable and `2.63.14` patched, while this proof reproduces on current `master` / `v2.63.15` (`be23ab3a15bf957928ecfed88de5ab67850c1b9c`). The escaping-symlink-to-an-existing-target case is defended and tested. The dangling case is neither, and the gap is acknowledged in a code comment as &amp;#34;best-effort&amp;#34;.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;`files/scoped.go` (commit `be23ab3`). The guard, including the ma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`ScopedFs` confines every File Browser user to a scope directory. Its `within()` guard is meant to reject any operation that follows a symbolic link out of that scope. When the link target does not exist yet, the guard walks up to the nearest existing ancestor and validates that instead. For a dangling symlink (target does not exist), the nearest existing ancestor is the in-scope directory containing the link, so the guard returns &amp;#34;in scope&amp;#34; and the subsequent `os.OpenFile(O_CREATE)` follows the link and creates the file at its out-of-scope target.&lt;/p&gt;
&lt;p&gt;A post-auth user with `Create` and `Modify` permission can write attacker-controlled content to any non-existent path outside their scope that the File Browser process can write to. The precondition is a dangling symlink present inside the user&amp;#39;s scope, which is the same out-of-band precondition the rest of `ScopedFs` is built to defend against.&lt;/p&gt;
&lt;p&gt;This is a patch-gap variant of the GHSA-239w-m3h6-ch8v symlink confinement issue, not a resubmission of the already-published vulnerable-version behavior: GHSA-239w-m3h6-ch8v marks `&amp;lt;= 2.63.13` vulnerable and `2.63.14` patched, while this proof reproduces on current `master` / `v2.63.15` (`be23ab3a15bf957928ecfed88de5ab67850c1b9c`). The escaping-symlink-to-an-existing-target case is defended and tested. The dangling case is neither, and the gap is acknowledged in a code comment as &amp;#34;best-effort&amp;#34;.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;`files/scoped.go` (commit `be23ab3`). The guard, including the ma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8wc8-hf36-mjh9</guid>
    </item>
  </channel>
</rss>
