<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T20:28:46.933379+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-327392</id>
    <title>EUVD-2026-327392</title>
    <updated>2026-10-05T20:28:46.978594+00:00</updated>
    <content>EUVD-2026-327392</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-327392"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45012</id>
    <title>fkie_cve-2026-45012</title>
    <updated>2026-10-05T20:28:46.978631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget import flow. An authenticated user who can submit/edit rich-text widget content can cause the server to fetch attacker-controlled URLs during widget validation. For image-compatible responses, the fetched content can be persisted and re-hosted by Apostrophe, allowing response exfiltration. As of time of publication, no known patched versions are available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pr28-mf3q-qpg6</id>
    <title>GHSA-pr28-mf3q-qpg6 — Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget</title>
    <updated>2026-10-05T20:28:46.978665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: apostrophe</p>
<p>### Summary
ApostropheCMS contains an authenticated server-side request forgery (SSRF) in the rich-text widget import flow. An authenticated user who can submit/edit rich-text widget content can cause the server to fetch attacker-controlled URLs during widget validation. For image-compatible responses, the fetched content can be persisted and re-hosted by Apostrophe, allowing response exfiltration.</p>
<p>### Details
  The vulnerable flow is in the rich-text widget sanitizer:
  - `packages/apostrophe/modules/@apostrophecms/rich-text-widget/index.js`
  - `packages/apostrophe/modules/@apostrophecms/area/index.js`
  - `packages/apostrophe/modules/@apostrophecms/widget-type/index.js`</p>
<p>Relevant behavior:
  1. The backend accepts a widget payload containing `import.html`.
  2. It parses `&lt;img src=...&gt;` values from that HTML.
  3. For each image, it resolves the URL with:
     - `new URL(src, input.import.baseUrl || self.apos.baseUrl)`
  4. It then performs a server-side `fetch(url)`.
  5. The fetched body is written to a temp file and imported through Apostrophe image/attachment logic.</p>
<p>This is reachable during widget validation through:
  - `POST /api/v1/@apostrophecms/area/validate-widget?aposMode=draft`</p>
<p>### PoC
 1. Start a local HTTP server with a valid PNG:
```bash
     mkdir -p /tmp/apos-poc
     base64 -d &gt; /tmp/apos-poc/secret.png &lt;&lt;'EOF'
     iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8/x8AAwMCAO+y1n0AAAAASUVORK5CYII=
     EOF
     cd /tmp/apos-poc &amp;&amp; python3…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pr28-mf3q-qpg6"/>
  </entry>
</feed>
