<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T05:38:08.001409+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343789</id>
    <title>EUVD-2026-343789</title>
    <updated>2026-10-06T05:38:08.003740+00:00</updated>
    <content>EUVD-2026-343789</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45376</id>
    <title>fkie_cve-2026-45376</title>
    <updated>2026-10-06T05:38:08.003772+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions before sanitization, allowing an authenticated organization administrator to execute blind PostgreSQL expressions and infer data through timing differences. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45376"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jvqq-cvh4-xm37</id>
    <title>GHSA-jvqq-cvh4-xm37 — Decidim: Admin user search allows SQL injection through similarity-based sorting</title>
    <updated>2026-10-06T05:38:08.003804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: decidim-admin</p>
<p>The admin organization user search uses the untrusted term value inside raw SQL ORDER BY expressions. Because the value is interpolated before Rails sanitization is applied, a crafted search string is executed by PostgreSQL as part of the sort expression.</p>
<p>### Technical description
 
The vulnerable endpoint is exposed as GET `/admin/organization/users` in `decidim-admin/config/routes.rb`:</p>
<p>```ruby
resource :organization, only: [:edit, :update], controller: "organization" do
  member do
    get :users
  end
end
```</p>
<p>That route reaches `Decidim::Admin::OrganizationController#users`, which forwards the current organization's available users into `search`:</p>
<p>```ruby
def users
  search(current_organization.users.available)
end
```</p>
<p>Inside `search`, the attacker-controlled source is `params[:term]`:</p>
<p>```ruby
if (term = params[:term].to_s).present?
```</p>
<p>The query has two branches. In both branches, the `WHERE` predicates use bind parameters and are not the injection sink. The vulnerability is in the subsequent `.order(Arel.sql(...))` calls, where the untrusted value is interpolated directly into SQL string literals.</p>
<p>Nickname branch:</p>
<p>```ruby
nickname = term.delete("@")
relation.where("nickname LIKE ?", "#{nickname}%")
  .order(Arel.sql(ActiveRecord::Base.sanitize_sql_array("similarity(nickname, '#{nickname}') DESC")))
```</p>
<p>Name/email branch:</p>
<p>```ruby
relation.where("name ILIKE ?", "%#{term}%").or(
  relation.where("email ILIKE ?", "%#{term}%")
)
  .order(Arel.sql(ActiveRecord::Base…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jvqq-cvh4-xm37"/>
  </entry>
</feed>
