<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 14:47:54 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-354895</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-354895</link>
      <description>EUVD-2026-354895</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-354895</guid>
    </item>
    <item>
      <title>fkie_cve-2026-74907</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-74907</link>
      <description>&lt;p&gt;Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling directories by exploiting directory names that extend the base path string, such as requesting assets-secret when assets is the configured base.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling directories by exploiting directory names that extend the base path string, such as requesting assets-secret when assets is the configured base.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-74907</guid>
    </item>
    <item>
      <title>GHSA-4v9q-p283-qc2m — Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4v9q-p283-qc2m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;**Verified against:** `getgrav/grav` devel branch, `GRAV_VERSION = &amp;#34;2.0.15&amp;#34;`, file `index.php&lt;/p&gt;
&lt;p&gt;## Title
Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)&lt;/p&gt;
&lt;p&gt;## Product / Affected Versions
- Product: `getgrav/grav`
- File: `index.php` (top-level front controller, runs before Grav itself boots)
- Confirmed present in: devel branch, 2.0.15
- **Precondition:** requires `user/config/plugin-asset-map.php` to exist and contain at least one route-prefix mapping ,this is an opt-in mechanism (per the code comment: &amp;#34;Fast static asset serving for plugins that bundle SPA apps&amp;#34;). No core mechanism generates this file automatically; it&amp;#39;s created by a plugin that opts into this fast-path. **Not reachable on a stock Grav install with no such plugin.** Where reachable, it requires zero authentication.&lt;/p&gt;
&lt;p&gt;## CWE
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;) , specific mechanism: a path-prefix containment check performed with plain string comparison (`str_starts_with`) instead of a directory-boundary-aware comparison, allowing escape into any sibling path whose name happens to extend the base directory&amp;#39;s name as a string.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;`index.php` implements a fast-path static file server that runs *before* Grav&amp;#39;s own routing/security stack, gated on the presence of an asset-map file:&lt;/p&gt;
&lt;p&gt;```php
$assetMapFile = __DIR__ . &amp;#39;/user/config/plugin-asset-map.php&amp;#39;;
if (is_file($assetMapFil…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;**Verified against:** `getgrav/grav` devel branch, `GRAV_VERSION = &amp;#34;2.0.15&amp;#34;`, file `index.php&lt;/p&gt;
&lt;p&gt;## Title
Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)&lt;/p&gt;
&lt;p&gt;## Product / Affected Versions
- Product: `getgrav/grav`
- File: `index.php` (top-level front controller, runs before Grav itself boots)
- Confirmed present in: devel branch, 2.0.15
- **Precondition:** requires `user/config/plugin-asset-map.php` to exist and contain at least one route-prefix mapping ,this is an opt-in mechanism (per the code comment: &amp;#34;Fast static asset serving for plugins that bundle SPA apps&amp;#34;). No core mechanism generates this file automatically; it&amp;#39;s created by a plugin that opts into this fast-path. **Not reachable on a stock Grav install with no such plugin.** Where reachable, it requires zero authentication.&lt;/p&gt;
&lt;p&gt;## CWE
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;) , specific mechanism: a path-prefix containment check performed with plain string comparison (`str_starts_with`) instead of a directory-boundary-aware comparison, allowing escape into any sibling path whose name happens to extend the base directory&amp;#39;s name as a string.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;`index.php` implements a fast-path static file server that runs *before* Grav&amp;#39;s own routing/security stack, gated on the presence of an asset-map file:&lt;/p&gt;
&lt;p&gt;```php
$assetMapFile = __DIR__ . &amp;#39;/user/config/plugin-asset-map.php&amp;#39;;
if (is_file($assetMapFil…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4v9q-p283-qc2m</guid>
    </item>
  </channel>
</rss>
