<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T20:44:57.482318+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265738</id>
    <title>EUVD-2026-265738</title>
    <updated>2026-10-08T20:44:57.485893+00:00</updated>
    <content>EUVD-2026-265738</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265738"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22814</id>
    <title>fkie_cve-2026-22814</title>
    <updated>2026-10-08T20:44:57.485928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>@adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assignment vulnerability in AdonisJS Lucid which may allow a remote attacker who can influence data that is passed into Lucid model assignments to overwrite the internal ORM state. This may lead to logic bypasses and unauthorized record modification within a table or model. This affects @adonisjs/lucid through version 21.8.1 and 22.x pre-release versions prior to 22.0.0-next.6. This has been patched in @adonisjs/lucid versions 21.8.2 and 22.0.0-next.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22814"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g5gc-h5hp-555f</id>
    <title>GHSA-g5gc-h5hp-555f — Mass Assignment in AdonisJS Lucid Allows Overwriting Internal ORM State</title>
    <updated>2026-10-08T20:44:57.485962+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @adonisjs/lucid</p>
<p>### Summary
**Description**
A Mass Assignment (CWE-915) vulnerability in AdonisJS Lucid may allow a remote attacker who can influence data that is passed into Lucid model assignments to overwrite the internal ORM state. This may lead to logic bypasses and unauthorized record modification within a table or model. This affects @adonisjs/lucid through version 21.8.1 and 22.x pre-release versions prior to 22.0.0-next.6. This has been patched in @adonisjs/lucid versions 21.8.2 and 22.0.0-next.6.</p>
<p>### Details
A vulnerability in the `BaseModelImpl` class of `@adonisjs/lucid` may allow an attacker to overwrite internal class properties (such as `$isPersisted`, `$attributes`, or `$isDeleted`) when passing plain objects to model assignment methods.</p>
<p>The library relies on a `this.hasOwnProperty(key)` check to validate assignment targets. However, because internal ORM state properties are initialized as instance properties, they pass this check. Consequently, if an attacker can influence specific keys (like `$isPersisted`) into the payload passed to `merge()` or `$consumeAdapterResult()`, they can hijack the ORM's internal logic.</p>
<p>The exposed internal properties include:
- `$attributes`: The raw storage for model data.
- `$isPersisted`: Controls whether `save()` performs an `INSERT` or an `UPDATE`.
- `$original`: Stores the original state of the record used to calculate changes.
- `$isDeleted`: Prevents operations on deleted models.</p>
<p>This issue propagates to the entire write surface of…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g5gc-h5hp-555f"/>
  </entry>
</feed>
