<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T20:11:20.891326+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292932</id>
    <title>EUVD-2026-292932</title>
    <updated>2026-10-08T20:11:20.945758+00:00</updated>
    <content>EUVD-2026-292932</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292932"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41067</id>
    <title>fkie_cve-2026-41067</title>
    <updated>2026-10-08T20:11:20.945799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /&lt;\/script&gt;/g to sanitize values injected into inline &lt;script&gt; tags via the define:vars directive. HTML parsers close &lt;script&gt; elements case-insensitively and also accept whitespace or / before the closing &gt;, allowing an attacker to bypass the sanitization with payloads like &lt;/Script&gt;, &lt;/script &gt;, or &lt;/script/&gt; and inject arbitrary HTML/JavaScript. This vulnerability is fixed in 6.1.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j687-52p2-xcff</id>
    <title>GHSA-j687-52p2-xcff — Astro: XSS in define:vars via incomplete &lt;/script&gt; tag sanitization</title>
    <updated>2026-10-08T20:11:20.945837+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: astro</p>
<p>## Summary</p>
<p>The `defineScriptVars` function in Astro's server-side rendering pipeline uses a case-sensitive regex `/&lt;\/script&gt;/g` to sanitize values injected into inline `&lt;script&gt;` tags via the `define:vars` directive. HTML parsers close `&lt;script&gt;` elements case-insensitively and also accept whitespace or `/` before the closing `&gt;`, allowing an attacker to bypass the sanitization with payloads like `&lt;/Script&gt;`, `&lt;/script &gt;`, or `&lt;/script/&gt;` and inject arbitrary HTML/JavaScript.</p>
<p>## Details</p>
<p>The vulnerable function is `defineScriptVars` at `packages/astro/src/runtime/server/render/util.ts:42-53`:</p>
<p>```typescript
export function defineScriptVars(vars: Record&lt;any, any&gt;) {
	let output = '';
	for (const [key, value] of Object.entries(vars)) {
		output += `const ${toIdent(key)} = ${JSON.stringify(value)?.replace(
			/&lt;\/script&gt;/g,       // ← Case-sensitive, exact match only
			'\\x3C/script&gt;',
		)};\n`;
	}
	return markHTMLString(output);
}
```</p>
<p>This function is called from `renderElement` at `util.ts:172-174` when a `&lt;script&gt;` element has `define:vars`:</p>
<p>```typescript
if (name === 'script') {
	delete props.hoist;
	children = defineScriptVars(defineVars) + '\n' + children;
}
```</p>
<p>The regex `/&lt;\/script&gt;/g` fails to match three classes of closing script tags that HTML parsers accept per the [HTML specification §13.2.6.4](https://html.spec.whatwg.org/multipage/parsing.html#parsing-main-inbody):</p>
<p>1. **Case variations**: `&lt;/Script&gt;`, `&lt;/SCRIPT&gt;`, `&lt;/sCrIpT&gt;` — HTML tag names are case-ins…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j687-52p2-xcff"/>
  </entry>
</feed>
