<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T14:11:07.568828+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-157879</id>
    <title>EUVD-2026-157879</title>
    <updated>2026-10-06T14:11:07.614457+00:00</updated>
    <content>EUVD-2026-157879</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-157879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-41677</id>
    <title>fkie_cve-2024-41677</title>
    <updated>2026-10-06T14:11:07.614495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly escapes HTML on server-side rendering. It converts strings according to the rules found in the `render-ssr.ts` file. It sometimes causes the situation that the final DOM tree rendered on browsers is different from what Qwik expects on server-side rendering. This may be leveraged to perform XSS attacks, and a type of the XSS is known as mXSS (mutation XSS). This has been resolved in qwik version 1.6.0 and @builder.io/qwik version 1.7.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-41677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2rwj-7xq8-4gx4</id>
    <title>GHSA-2rwj-7xq8-4gx4 — Qwik has a potential mXSS vulnerability due to improper HTML escaping</title>
    <updated>2026-10-06T14:11:07.614530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @builder.io/qwik</p>
<p>### Summary</p>
<p>A potential mXSS vulnerability exists in Qwik for versions up to 1.6.0.</p>
<p>### Details</p>
<p>Qwik improperly escapes HTML on server-side rendering. It converts strings according to the following rules:</p>
<p>https://github.com/QwikDev/qwik/blob/v1.5.5/packages/qwik/src/core/render/ssr/render-ssr.ts#L1182-L1208</p>
<p>- If the string is an attribute value:
    - `"` -&gt; `&amp;quot;`
    - `&amp;` -&gt; `&amp;amp;`
    - Other characters -&gt; No conversion
- Otherwise:
    - `&lt;` -&gt; `&amp;lt;`
    - `&gt;` -&gt; `&amp;gt;`
    - `&amp;` -&gt; `&amp;amp;`
    - Other characters -&gt; No conversion</p>
<p>It sometimes causes the situation that the final DOM tree rendered on browsers is different from what Qwik expects on server-side rendering. This may be leveraged to perform XSS attacks, and a type of the XSS is known as mXSS (mutation XSS).</p>
<p>## PoC</p>
<p>A vulnerable component:
```javascript
import { component$ } from "@builder.io/qwik";
import { useLocation } from "@builder.io/qwik-city";</p>
<p>export default component$(() =&gt; {
  
  // user input
  const { url } = useLocation();
  const href = url.searchParams.get("href") ?? "https://example.com";</p>
<p>return (
    &lt;div&gt;
      &lt;noscript&gt;
        &lt;a href={href}&gt;test&lt;/a&gt;
      &lt;/noscript&gt;
    &lt;/div&gt;
  );
});
```</p>
<p>If a user accesses the following URL,
```
http://localhost:4173/?href=&lt;/noscript&gt;&lt;script&gt;alert(123)&lt;/script&gt;
```
then, `alert(123)` will be executed.</p>
<p>### Impact</p>
<p>XSS</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2rwj-7xq8-4gx4"/>
  </entry>
</feed>
