<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:08:39.269515+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322581</id>
    <title>EUVD-2026-322581</title>
    <updated>2026-10-02T22:08:39.348698+00:00</updated>
    <content>EUVD-2026-322581</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45348</id>
    <title>fkie_cve-2026-45348</title>
    <updated>2026-10-02T22:08:39.348743+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates a stored link URL into a template literal inside single-quoted HTML and then writes the result to the DOM via $(div).html(html). No escaping runs between the API value and innerHTML. An attacker (Alice) who can submit a package link puts a single quote plus event handler into the URL, breaks out of the attribute, and executes JavaScript in every operator's browser that opens the downloads view. The theme does not set a Content Security Policy that restricts inline script or event handlers. This vulnerability is fixed in 0.5.0b3.dev100.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fcjq-435v-jx94</id>
    <title>GHSA-fcjq-435v-jx94 — pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal</title>
    <updated>2026-10-02T22:08:39.348793+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyload-ng</p>
<p>## Summary</p>
<p>The `packages.js` template at `src/pyload/webui/app/themes/modern/templates/js/packages.js:172` interpolates a stored link URL into a template literal inside single-quoted HTML and then writes the result to the DOM via `$(div).html(html)`. No escaping runs between the API value and `innerHTML`. An attacker (Alice) who can submit a package link puts a single quote plus event handler into the URL, breaks out of the attribute, and executes JavaScript in every operator's browser that opens the downloads view. The theme does not set a Content Security Policy that restricts inline script or event handlers.</p>
<p>## Details</p>
<p>**Sink**: `src/pyload/webui/app/themes/modern/templates/js/packages.js:165-188`:</p>
<p>```javascript
const html = `
    &lt;span class='child_status'&gt;
      &lt;span style='margin-right: 2px;color: #337ab7;' class='${link.icon}'&gt;&lt;/span&gt;
    &lt;/span&gt;
    &lt;span style='font-size: 16px; font-weight: bold;'&gt;
      &lt;a onclick='return false' href='${link.url}'&gt;${link.name}&lt;/a&gt;
    &lt;/span&gt;&lt;br/&gt;
    &lt;div class='child_secrow' ...&gt;
      &lt;span class='child_status' ...&gt;${link.statusmsg}&lt;/span&gt;&amp;nbsp;${link.error}&amp;nbsp;
      &lt;span class='child_status' ...&gt;${link.format_size}&lt;/span&gt;
      &lt;span class='child_status' ...&gt; ${link.plugin}&lt;/span&gt;...
    &lt;/div&gt;`;</p>
<p>const div = document.createElement("div");
$(div).attr("id", `file_${link.id}`);
$(div).css("padding-left", "30px");
$(div).css("cursor", "grab");
$(div).addClass("child");
$(div).html(html);
```</p>
<p>`link.url` flows in from `/a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fcjq-435v-jx94"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2994</id>
    <title>PYSEC-2026-2994 — pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal</title>
    <updated>2026-10-02T22:08:39.348889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyload-ng</p>
<p>## Summary</p>
<p>The `packages.js` template at `src/pyload/webui/app/themes/modern/templates/js/packages.js:172` interpolates a stored link URL into a template literal inside single-quoted HTML and then writes the result to the DOM via `$(div).html(html)`. No escaping runs between the API value and `innerHTML`. An attacker (Alice) who can submit a package link puts a single quote plus event handler into the URL, breaks out of the attribute, and executes JavaScript in every operator's browser that opens the downloads view. The theme does not set a Content Security Policy that restricts inline script or event handlers.</p>
<p>## Details</p>
<p>**Sink**: `src/pyload/webui/app/themes/modern/templates/js/packages.js:165-188`:</p>
<p>```javascript
const html = `
    &lt;span class='child_status'&gt;
      &lt;span style='margin-right: 2px;color: #337ab7;' class='${link.icon}'&gt;&lt;/span&gt;
    &lt;/span&gt;
    &lt;span style='font-size: 16px; font-weight: bold;'&gt;
      &lt;a onclick='return false' href='${link.url}'&gt;${link.name}&lt;/a&gt;
    &lt;/span&gt;&lt;br/&gt;
    &lt;div class='child_secrow' ...&gt;
      &lt;span class='child_status' ...&gt;${link.statusmsg}&lt;/span&gt;&amp;nbsp;${link.error}&amp;nbsp;
      &lt;span class='child_status' ...&gt;${link.format_size}&lt;/span&gt;
      &lt;span class='child_status' ...&gt; ${link.plugin}&lt;/span&gt;...
    &lt;/div&gt;`;</p>
<p>const div = document.createElement("div");
$(div).attr("id", `file_${link.id}`);
$(div).css("padding-left", "30px");
$(div).css("cursor", "grab");
$(div).addClass("child");
$(div).html(html);
```</p>
<p>`link.url` flows in from `/a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2994"/>
  </entry>
</feed>
