<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T09:09:12.598384+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338960</id>
    <title>EUVD-2026-338960</title>
    <updated>2026-10-09T09:09:12.645590+00:00</updated>
    <content>EUVD-2026-338960</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338960"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54498</id>
    <title>fkie_cve-2026-54498</title>
    <updated>2026-10-09T09:09:12.645630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied to normal #call return values. This creates an XSS risk when downstream applications use around_render to wrap, replace, instrument, or conditionally return content that includes user-controlled data, and ViewComponent::Collection#render_in can amplify the issue by joining per-item results and marking the entire output html_safe, converting raw unsafe output into an ActiveSupport::SafeBuffer. This issue is fixed in version 4.12.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-97jw-64cj-jc58</id>
    <title>GHSA-97jw-64cj-jc58 — ViewComponent: around_render HTML-Safety Bypass</title>
    <updated>2026-10-09T09:09:12.645666+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: view_component</p>
<p>## Summary</p>
<p>`ViewComponent::Base#around_render` can return HTML-unsafe strings that bypass the escaping behavior applied to normal `#call` return values. This creates an XSS risk when downstream applications use `around_render` to wrap, replace, instrument, or conditionally return content that includes user-controlled data.</p>
<p>The issue is especially dangerous in collection rendering because `ViewComponent::Collection#render_in` joins the per-item results and marks the entire output as `html_safe`, converting raw unsafe output into a trusted `ActiveSupport::SafeBuffer`.</p>
<p>## Affected Code</p>
<p>Validated against:</p>
<p>- Repository commit: `eea79445`
- Ruby: `3.4.9`</p>
<p>Relevant locations:</p>
<p>- `lib/view_component/base.rb`
  - `render_in`
  - `around_render`
  - `__vc_maybe_escape_html`
- `lib/view_component/template.rb`
  - `InlineCall#safe_method_name_call`
- `lib/view_component/collection.rb`
  - `Collection#render_in`</p>
<p>Key code paths:</p>
<p>```ruby
# lib/view_component/base.rb
around_render do
  render_template_for(@__vc_requested_details).to_s
end
```</p>
<p>```ruby
# lib/view_component/template.rb
proc do
  __vc_maybe_escape_html(send(m)) do
    Kernel.warn(...)
  end
end
```</p>
<p>```ruby
# lib/view_component/collection.rb
components.map do |component|
  component.render_in(view_context, &amp;block)
end.join(rendered_spacer(view_context)).html_safe
```</p>
<p>## Root Cause</p>
<p>Normal inline `#call` output is passed through `__vc_maybe_escape_html`, which escapes HTML-unsafe strings. However, when `around_render`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-97jw-64cj-jc58"/>
  </entry>
</feed>
