<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:32:31.535064+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09394</id>
    <title>bdu:2026-09394</title>
    <updated>2026-10-03T12:32:31.646422+00:00</updated>
    <content>bdu:2026-09394</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0581</id>
    <title>certfr-2026-avi-0581 — De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-03T12:32:31.646460+00:00</updated>
    <content>certfr-2026-avi-0581</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</id>
    <title>Withdrawn: CLEANSTART-2026-AD27625 — Security fixes for CVE-2022-25881, CVE-2022-33987, CVE-2025-25285, CVE-2025-62718, CVE-2025-69873, CVE-2026-21637, CVE-…</title>
    <updated>2026-10-03T12:32:31.646478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: mongosh</p>
<p>Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278137</id>
    <title>EUVD-2026-278137</title>
    <updated>2026-10-03T12:32:31.646511+00:00</updated>
    <content>EUVD-2026-278137</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278137"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33916</id>
    <title>fkie_cve-2026-33916</title>
    <updated>2026-10-03T12:32:31.646523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS. Version 4.7.9 fixes the issue. Some workarounds are available. Apply `Object.freeze(Object.prototype)` early in application startup to prevent prototype  pollution. Note: this may break other libraries, and/or use the Handlebars runtime-only build (`handlebars/runtime`), which does not compile templates  and reduces the attack surface.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33916"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2qvq-rjwj-gvw9</id>
    <title>GHSA-2qvq-rjwj-gvw9 — Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection</title>
    <updated>2026-10-03T12:32:31.646547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: handlebars</p>
<p>## Summary</p>
<p>`resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered **without HTML escaping**, resulting in reflected or stored XSS.</p>
<p>## Description</p>
<p>The root cause is in `lib/handlebars/runtime.js` inside `resolvePartial()` and `invokePartial()`:</p>
<p>```javascript
// Vulnerable: plain bracket access traverses Object.prototype
partial = options.partials[options.name];
```</p>
<p>`hasOwnProperty` is never checked, so if `Object.prototype` has been seeded with a key whose name matches a partial reference in the template (e.g. `widget`), the lookup succeeds and the polluted string is returned. The runtime emits a prototype-access warning, but the partial is still resolved and its content is inserted into the rendered output unescaped. This contradicts the documented security model and is distinct from CVE-2021-23369 and CVE-2021-23383, which addressed data property access rather than partial template resolution.</p>
<p>**Prerequisites for exploitation:**
1. The target application must be vulnerable to prototype pollution (e.g. via `qs`, `minimist`, or
   any querystring/JSON merge sink).
2. The attacker must know or guess the name of a partial reference used in a template.</p>
<p>## Proof of Concept</p>
<p>```javascript…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2qvq-rjwj-gvw9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-33916</id>
    <title>msrc_CVE-2026-33916 — Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection</title>
    <updated>2026-10-03T12:32:31.646591+00:00</updated>
    <content>msrc_CVE-2026-33916</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-33916"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33916</id>
    <title>UBUNTU-CVE-2026-33916</title>
    <updated>2026-10-03T12:32:31.646607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-handlebars, Ubuntu:20.04:LTS: node-handlebars, Ubuntu:22.04:LTS: node-handlebars, Ubuntu:24.04:LTS: node-handlebars, Ubuntu:25.10: node-handlebars, Ubuntu:26.04:LTS: node-handlebars</p>
<p>Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS. Version 4.7.9 fixes the issue. Some workarounds are available. Apply `Object.freeze(Object.prototype)` early in application startup to prevent prototype  pollution. Note: this may break other libraries, and/or use the Handlebars runtime-only build (`handlebars/runtime`), which does not compile templates  and reduces the attack surface.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33916"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</id>
    <title>WID-SEC-W-2026-1407 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:32:31.646637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407"/>
  </entry>
</feed>
