<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T14:40:34.026285+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-328826</id>
    <title>EUVD-2026-328826</title>
    <updated>2026-10-08T14:40:34.028467+00:00</updated>
    <content>EUVD-2026-328826</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-328826"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56382</id>
    <title>fkie_cve-2026-56382</title>
    <updated>2026-10-08T14:40:34.028498+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Craft CMS (composer package craftcms/cms) versions &gt;= 5.5.0 and &lt;= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fieldLayoutConfig POST parameter directly to Fields::createLayout() without calling Component::cleanseConfig(). An authenticated admin user can inject Yii2 event handlers (e.g., 'on init' keys) via the fieldLayoutConfig parameter to execute arbitrary PHP code and disclose sensitive information (such as environment variables containing database credentials and CRAFT_SECURITY_KEY). The issue is fixed in version 5.9.14.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-56382"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-86vw-x4ww-x467</id>
    <title>GHSA-86vw-x4ww-x467 — Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview</title>
    <updated>2026-10-08T14:40:34.028532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: craftcms/cms</p>
<p>The `actionRenderCardPreview()` method in `FieldsController` passes the `fieldLayoutConfig` POST parameter directly to `Fields::createLayout()` without calling `Component::cleanseConfig()`. This allows Yii2 event handler injection via `on eventName` keys in the config array, leading to arbitrary code execution.</p>
<p>This is the same vulnerability pattern that was fixed in GHSA-4484-8v2f-5748 (same file, `_fldComponent` method correctly uses `cleanseConfig`), GHSA-qx2q-q59v-wf3j (EntryTypesController), and GHSA-2fph-6v5w-89hh (ElementIndexesController).</p>
<p>## PoC</p>
<p>As an admin user with a valid session:</p>
<p>```
POST /admin/actions/fields/render-card-preview HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Cookie: CraftSessionId=&lt;session&gt;</p>
<p>fieldLayoutConfig[on+init]=phpinfo&amp;CRAFT_CSRF_TOKEN=&lt;token&gt;
```</p>
<p>When the FieldLayout object is constructed, Yii2 processes the `on init` key as an event handler registration. During `Component::init()`, the `init` event is triggered, calling `phpinfo()`. The phpinfo output (which includes environment variables, potentially containing database credentials and `CRAFT_SECURITY_KEY`) will appear in the response.</p>
<p>## Impact</p>
<p>An authenticated admin can achieve RCE through Yii2 event handler injection. While this requires admin access (same as GHSA-4484-8v2f-5748, which was rated moderate), it allows arbitrary PHP function execution and information disclosure via phpinfo.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-86vw-x4ww-x467"/>
  </entry>
</feed>
