<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T22:17:56.181366+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277343</id>
    <title>EUVD-2026-277343</title>
    <updated>2026-10-05T22:17:56.246073+00:00</updated>
    <content>EUVD-2026-277343</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277343"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33331</id>
    <title>fkie_cve-2026-33331</title>
    <updated>2026-10-05T22:17:56.246115+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.9, a stored cross-site scripting (XSS) vulnerability exists in the OpenAPI documentation generation of orpc. If an attacker can control any field within the OpenAPI specification (such as info.description), they can break out of the JSON context and execute arbitrary JavaScript when a user views the generated API documentation. This issue has been patched in version 1.13.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33331"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7f6v-3gx7-27q8</id>
    <title>GHSA-7f6v-3gx7-27q8 — oRPC has Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify</title>
    <updated>2026-10-05T22:17:56.246153+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @orpc/openapi</p>
<p>A Stored Cross-Site Scripting (XSS) vulnerability exists in the OpenAPI documentation generation of orpc. If an attacker can control any field within the OpenAPI specification (such as info.description), they can break out of the JSON context and execute arbitrary JavaScript when a user views the generated API documentation.
In the packages/openapi/src/plugins/openapi-reference.ts file, the renderDocsHtml() function takes an OpenAPI spec object and embeds it directly into the HTML response using a template literal:</p>
<p>`&lt;script id="spec" type="application/json"&gt;${JSON.stringify(spec)}&lt;/script&gt;`</p>
<p>The JSON.stringify() function does not escape HTML characters like &lt; or &gt;. Therefore, if an attacker provides a string containing &lt;/script&gt;&lt;script&gt;..., the browser will prematurely close the application/json script block and execute the subsequent malicious script block.</p>
<p>Proof of Concept (PoC)</p>
<p>1. Create an API router with **orpc** and configure the OpenAPI plugin.
2. In the API specification, inject a malicious payload into a field like **description**:</p>
<p>```
{
info: {
title: "My API",
version: "1.0.0",
description: "&lt;/script&gt;&lt;script&gt;alert('XSS executed on ' + document.domain)&lt;/script&gt;"
}
}
```</p>
<p>3. Generate and serve the documentation HTML.
4. When a developer or user navigates to the API documentation URL, the browser parses the HTML, breaks out of the JSON block, and immediately executes the **alert()** payload.</p>
<p>Impact</p>
<p>If an application generates its OpenAPI specifications dynamica…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7f6v-3gx7-27q8"/>
  </entry>
</feed>
