<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:18:41.293689+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07547</id>
    <title>bdu:2026-07547</title>
    <updated>2026-10-03T01:18:41.296356+00:00</updated>
    <content>bdu:2026-07547</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292035</id>
    <title>EUVD-2026-292035</title>
    <updated>2026-10-03T01:18:41.296387+00:00</updated>
    <content>EUVD-2026-292035</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40922</id>
    <title>fkie_cve-2026-40922</title>
    <updated>2026-10-03T01:18:41.296401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in bazaar README rendering (incomplete fix for CVE-2026-33066) enabled the Lute HTML sanitizer, but the sanitizer does not block iframe tags, and its URL-prefix blocklist does not effectively filter srcdoc attributes which contain raw HTML rather than URLs. A malicious bazaar package author can include an iframe with a srcdoc attribute containing embedded scripts in their README. When other users view the package in SiYuan's marketplace UI, the payload executes in the Electron context with full application privileges, enabling arbitrary code execution on the user's machine. This issue has been fixed in version 3.6.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8q5w-mmxf-48jg</id>
    <title>GHSA-8q5w-mmxf-48jg — SiYuan has incomplete fix for CVE-2026-33066: XSS</title>
    <updated>2026-10-03T01:18:41.296433+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/siyuan-note/siyuan/kernel</p>
<p>### Summary</p>
<p>The incomplete fix for SiYuan's bazaar README rendering enables the Lute HTML sanitizer but fails to block `&lt;iframe&gt;` tags, allowing stored XSS via `srcdoc` attributes containing embedded scripts that execute in the Electron context.</p>
<p>### Affected Package</p>
<p>- **Ecosystem:** Go
- **Package:** github.com/siyuan-note/siyuan
- **Affected versions:** &lt; commit b382f50e1880
- **Patched versions:** &gt;= commit b382f50e1880</p>
<p>### Details</p>
<p>The `renderPackageREADME()` function in `kernel/bazaar/readme.go` renders Markdown README content from bazaar (marketplace) packages into HTML. The original vulnerability allowed stored XSS through unsanitized HTML in READMEs. The fix adds `luteEngine.SetSanitize(true)` to enable Lute's built-in HTML sanitizer.</p>
<p>However, the Lute sanitizer in `lute/render/sanitizer.go` has a critical gap:
1. `&lt;iframe&gt;` is explicitly commented out of `setOfElementsToSkipContent`, so iframe tags pass through.
2. The `srcdoc` attribute is checked against URL-prefix blocklists (`javascript:`, `data:text/html`), but `srcdoc` contains raw HTML content, not a URL. A value like `&lt;img src=x onerror=alert(1)&gt;` does not start with any blocked prefix.
3. The browser renders `srcdoc` HTML in a nested browsing context, executing embedded scripts and event handlers.</p>
<p>The fix correctly blocks direct `&lt;script&gt;` tags, event handler attributes, and `javascript:` protocol links. However:</p>
<p>- `&lt;iframe srcdoc="&lt;script&gt;alert(document.domain)&lt;/script&gt;"&gt;` passes through because ifra…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8q5w-mmxf-48jg"/>
  </entry>
</feed>
