<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:29:27.656648+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232588</id>
    <title>EUVD-2026-232588</title>
    <updated>2026-10-03T10:29:27.730047+00:00</updated>
    <content>EUVD-2026-232588</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232588"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39322</id>
    <title>fkie_cve-2022-39322</title>
    <updated>2026-10-03T10:29:27.730089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if configured - are vulnerable to their field-level access control not being used. List-level access control is not affected. Field-level access control for fields other than `multiselect` are not affected. Version 2.3.1 contains a fix for this issue. As a workaround, stop using the `multiselect` field.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-39322"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6mhr-52mv-6v6f</id>
    <title>GHSA-6mhr-52mv-6v6f — Field-level access-control bypass for multiselect field</title>
    <updated>2026-10-03T10:29:27.730128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @keystone-6/core</p>
<p>#### Impact</p>
<p>`@keystone-6/core@2.2.0 || 2.3.0` users who are using the `multiselect` field, and provided field-level access control - are vulnerable to their field-level access control not being used.</p>
<p>List-level access control is **NOT** affected.</p>
<p>Field-level access control for fields other than `multiselect` are **NOT** affected.</p>
<p>Example, **you are vulnerable if** you are using field-level access control on a `multiselect` like the following:
```ts
const yourList = list({
  access: {
    // this is list-level access control, this is NOT impacted
  },
  fields: {
    yourFieldName: multiselect({
      // this is field-level access control, for multiselect fields
      //   this is vulnerable
      access: {
        create: ({ session }) =&gt; session?.data.isAdmin,
        update: ({ session }) =&gt; session?.data.isAdmin,
      },
      options: [
        { value: 'apples', label: 'Apples' },
        { value: 'oranges', label: 'Oranges' },
      ],
      // ...
    }),
    // ...
  },
  // ...
});
```</p>
<p>#### Mitigation
Please upgrade to `@keystone-6/core &gt;= 2.3.1`, where this vulnerability has been closed.</p>
<p>#### Workarounds
If for some reason you cannot upgrade your dependencies, you should stop using the `multiselect` field.</p>
<p>#### Credits
Thanks to [Marek R](https://github.com/marekryb) for reporting and submitting the pull request to fix this problem.</p>
<p>If you have any questions around this security advisory, please don't hesitate to contact us at [security@keystonejs.com](mai…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6mhr-52mv-6v6f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-39322</id>
    <title>gsd-2022-39322</title>
    <updated>2026-10-03T10:29:27.730179+00:00</updated>
    <content>gsd-2022-39322</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-39322"/>
  </entry>
</feed>
