<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T09:40:35.352111+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0660</id>
    <title>certfr-2026-avi-0660 — De multiples vulnérabilités ont été découvertes dans les produits Mattermost. Elles permettent à un attaquant de provoq…</title>
    <updated>2026-10-08T09:40:35.404747+00:00</updated>
    <content>certfr-2026-avi-0660</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0660"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330636</id>
    <title>EUVD-2026-330636</title>
    <updated>2026-10-08T09:40:35.404832+00:00</updated>
    <content>EUVD-2026-330636</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330636"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4339</id>
    <title>fkie_cve-2026-4339</title>
    <updated>2026-10-08T09:40:35.404848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mattermost versions 10.11.x &lt;= 10.11.18, 11.6.x &lt;= 11.6.3, 11.5.x &lt;= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate data from internal network services via supplying internal URLs as file attachments in post creation requests.. Mattermost Advisory ID: MMSA-2026-00635</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-4339"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p3qg-h7r3-79xr</id>
    <title>GHSA-p3qg-h7r3-79xr</title>
    <updated>2026-10-08T09:40:35.404880+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mattermost versions 10.11.x &lt;= 10.11.18, 11.6.x &lt;= 11.6.3, 11.5.x &lt;= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate data from internal network services via supplying internal URLs as file attachments in post creation requests.. Mattermost Advisory ID: MMSA-2026-00635</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p3qg-h7r3-79xr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1705</id>
    <title>WID-SEC-W-2026-1705 — Mattermost Server und Plugins: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-08T09:40:35.404898+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Mattermost Server und Plugins ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1705"/>
  </entry>
</feed>
