<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T11:19:49.624057+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-218028</id>
    <title>EUVD-2026-218028</title>
    <updated>2026-10-10T11:19:49.627178+00:00</updated>
    <content>EUVD-2026-218028</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-218028"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-25300</id>
    <title>fkie_cve-2025-25300</title>
    <updated>2026-10-10T11:19:49.627235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>smartbanner.js is a customizable smart app banner for iOS and Android. Prior to version 1.14.1, clicking on smartbanner `View` link and navigating to 3rd party page leaves `window.opener` exposed. It may allow hostile third parties to abuse `window.opener`, e.g. by redirection or injection on the original page with smartbanner. `rel="noopener"` is automatically populated to links as of `v1.14.1` which is a recommended upgrade to resolve the vulnerability. Some workarounds are available for those who cannot upgrade. Ensure `View` link is only taking users to App Store or Google Play Store where security is guarded by respective app store security teams. If `View` link is going to a third party page, limit smartbanner.js to be used on iOS that decreases the scope of the vulnerability since as of Safari 12.1,  `rel="noopener"` is imposed on all `target="_blank"` links. Version 1.14.1 of smartbanner.js contains a fix for the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-25300"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9mrq-cjgh-32g2</id>
    <title>GHSA-9mrq-cjgh-32g2 — smartbanner.js rel noopener vulnerability</title>
    <updated>2026-10-10T11:19:49.627282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: smartbanner.js</p>
<p>## rel noopener vulnerability</p>
<p>### Impact
Clicking on smartbanner _View_ link and navigating to 3rd party page leaves `window.opener` exposed. It may allow hostile 3rd parties to abuse `window.opener`, e.g. by redirection or injection on the original page with smartbanner.</p>
<p>### Patches
`rel="noopener"` is automatically populated to links as of `v1.14.1` which is a recommended upgrade to resolve the vulnerability.</p>
<p>### Workarounds
If you can not upgrade to `v1.14.1`:
1. Ensure _View_ link is only taking users to App Store or Google Play Store where security is guarded by respective app store security teams
2. If _View_ link is going to a 3rd party page, limit smartbanner.js to be used on iOS that decreases the scope of the vulnerability since as of Safari 12.1,  `rel="noopener"` is imposed on all `target="_blank"` links.</p>
<p>Following combination of smartbanner meta tags can be used to achieve the above:</p>
<p>```html
    &lt;meta name="smartbanner:enabled-platforms" content="none"&gt;
    &lt;meta name="smartbanner:include-user-agent-regex" content="Mobile.*Safari"&gt;
    ```</p>
<p>### References
* [About rel=noopener](https://mathiasbynens.github.io/rel-noopener/)
* [Safari 12.1 Release Notes](https://developer.apple.com/documentation/safari_release_notes/safari_12_1_release_notes#3130296)</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in [smartbanner.js](https://github.com/ain/smartbanner.js/issues/new)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9mrq-cjgh-32g2"/>
  </entry>
</feed>
