<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T15:41:52.280876+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-323410</id>
    <title>EUVD-2026-323410</title>
    <updated>2026-10-07T15:41:52.285065+00:00</updated>
    <content>EUVD-2026-323410</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-323410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44651</id>
    <title>fkie_cve-2026-44651</title>
    <updated>2026-10-07T15:41:52.285101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, when fetch(url) throws, the code sends:
res.status(500).send('Error occurred while trying to proxy to: ' + url + ' ' + error). The url value is attacker-controlled (req.params.url) and is not HTML-escaped before rendering. This vulnerability is fixed in 1.18.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xc4x-2452-5gc9</id>
    <title>GHSA-xc4x-2452-5gc9 — SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware</title>
    <updated>2026-10-07T15:41:52.285136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: sillytavern</p>
<p>## Resolution</p>
<p>Fixed in SillyTavern 1.18.0: a user-provided URL is no longer reflected in the HTTP response body.</p>
<p>## Overview
- Vulnerability Type: XSS
- Affected Location: `src/middleware/corsProxy.js:40`
- Trigger Scenario: reflected XSS in CORS proxy error response</p>
<p>## Root Cause
When `fetch(url)` throws, the code sends:
`res.status(500).send('Error occurred while trying to proxy to: ' + url + ' ' + error)`.
The `url` value is attacker-controlled (`req.params.url`) and is not HTML-escaped before rendering.</p>
<p>## Source-to-Sink Chain
1. Source (user-controlled input)
- Entry point: `GET /proxy/:url(*)`</p>
<p>2. Data flow
- Code analysis shows concrete propagation into this sink:
  - vulnerability title: `Reflected XSS in CORS proxy error response`
  - sink location reached by attacker-controlled input: `src/middleware/corsProxy.js:40`
- The same sink behavior is confirmed by controlled execution observations.</p>
<p>3. Sink (dangerous operation)
- Sink location: `src/middleware/corsProxy.js:40`
- Vulnerable behavior: reflected XSS in CORS proxy error response</p>
<p>## Exploitation Preconditions
1. The attacker can inject controllable content into a rendered response.
2. The vulnerable rendering context does not apply strict output encoding/sanitization.
3. A victim user opens the affected page or response.</p>
<p>## Risk
This issue enables script execution in the victim context and can compromise session or data integrity.</p>
<p>## Impact
An attacker may run arbitrary JavaScript in the victim context…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xc4x-2452-5gc9"/>
  </entry>
</feed>
