<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T07:48:54.396095+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278570</id>
    <title>EUVD-2026-278570</title>
    <updated>2026-10-07T07:48:54.441677+00:00</updated>
    <content>EUVD-2026-278570</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34605</id>
    <title>fkie_cve-2026-34605</title>
    <updated>2026-10-07T07:48:54.441713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to fix XSS in the unauthenticated /api/icon/getDynamicIcon endpoint can be bypassed by using namespace-prefixed element names such as &lt;x:script xmlns:x="http://www.w3.org/2000/svg"&gt;. The Go HTML5 parser records the element's tag as "x:script" rather than "script", so the tag check passes it through. The SVG is served with Content-Type: image/svg+xml and no Content Security Policy; when a browser opens the response directly, its XML parser resolves the prefix to the SVG namespace and executes the embedded script. This issue has been patched in version 3.6.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34605"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-73g7-86qr-jrg3</id>
    <title>GHSA-73g7-86qr-jrg3 — SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated)</title>
    <updated>2026-10-07T07:48:54.441749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/siyuan-note/siyuan/kernel</p>
<p>### Summary</p>
<p>The `SanitizeSVG` function introduced in v3.6.0 to fix XSS in the unauthenticated `/api/icon/getDynamicIcon` endpoint can be bypassed by using namespace-prefixed element names such as `&lt;x:script xmlns:x="http://www.w3.org/2000/svg"&gt;`. The Go HTML5 parser records the element's tag as `"x:script"` rather than `"script"`, so the tag check passes it through. The SVG is served with `Content-Type: image/svg+xml` and no Content Security Policy; when a browser opens the response directly, its XML parser resolves the prefix to the SVG namespace and executes the embedded script.</p>
<p>### Details</p>
<p>The `getDynamicIcon` route is registered without authentication:</p>
<p>```go
// kernel/server/serve.go
ginServer.Handle("GET", "/api/icon/getDynamicIcon", getDynamicIcon)
```</p>
<p>For type 8, the `content` query parameter is inserted directly into an SVG `&lt;text&gt;` element using `fmt.Sprintf` with no HTML encoding:</p>
<p>```go
// kernel/api/icon.go:579-584
return fmt.Sprintf(`
    &lt;svg id="dynamic_icon_type8" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512"&gt;
        &lt;path d="..."/&gt;
        &lt;text x="50%%" y="55%%" ...&gt;%s&lt;/text&gt;
    &lt;/svg&gt;`, ..., content)
```</p>
<p>`SanitizeSVG` then parses the SVG with `github.com/88250/lute/html` and removes elements whose lowercased tag name matches a fixed list:</p>
<p>```go
// kernel/util/misc.go:249-252
tag := strings.ToLower(c.Data)
if tag == "script" || tag == "iframe" || tag == "object" || tag == "embed" ||
    tag == "foreignobject" || "animate" == tag || ... {…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-73g7-86qr-jrg3"/>
  </entry>
</feed>
