<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T18:05:20.830131+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342032</id>
    <title>EUVD-2026-342032</title>
    <updated>2026-10-08T18:05:20.875783+00:00</updated>
    <content>EUVD-2026-342032</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59728</id>
    <title>fkie_cve-2026-59728</title>
    <updated>2026-10-08T18:05:20.875822+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by fast-xml-parser. Both fields are validated only as z.string(), placing no restriction on XML special characters. An attacker who controls these values can inject arbitrary XML into the generated RSS feed: a value containing " can break out of an attribute (as with enclosure.type), and a value containing &lt;/source&gt; can close an element early and inject additional nodes (as with source.title). This corrupts feed structure, injects false metadata (for example, a fake &lt;link&gt; pointing to a malicious URL), and can cause feed readers to misparse or display attacker-controlled content. In SSR mode (output: 'server'), the poisoned feed is served on every request to all subscribers. This issue has been fixed in version 4.0.19.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59728"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8j5q-mfj2-5q9q</id>
    <title>GHSA-8j5q-mfj2-5q9q — @astrojs/rss: XML Injection via Unescaped RSS Feed Fields</title>
    <updated>2026-10-08T18:05:20.875863+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @astrojs/rss</p>
<p>## Summary</p>
<p>In `@astrojs/rss`, the `source.title` and `enclosure.type` item fields are interpolated directly into XML template strings without XML-character escaping before being parsed by `fast-xml-parser`. An attacker who controls these field values can inject arbitrary XML elements into the generated RSS feed.</p>
<p>## Details</p>
<p>Two fields in `packages/astro-rss/src/index.ts` are affected:</p>
<p>### `source.title`</p>
<p>```typescript
item.source = parser.parse(
  `&lt;source url="${result.source.url}"&gt;${result.source.title}&lt;/source&gt;`,
).source;
```</p>
<p>`source.title` is validated only as `z.string()`, with no restriction on XML special characters. A value containing `&lt;/source&gt;` followed by arbitrary XML is parsed as real XML elements, merging injected nodes into the RSS item.</p>
<p>### `enclosure.type`</p>
<p>```typescript
item.enclosure = parser.parse(
  `&lt;enclosure url="${enclosureURL}" length="${result.enclosure.length}" type="${result.enclosure.type}"/&gt;`,
).enclosure;
```</p>
<p>`enclosure.type` is also `z.string()` and is interpolated into an XML attribute without escaping. A value containing `"` followed by additional XML can break out of the attribute and inject extra elements.</p>
<p>## Proof of Concept</p>
<p>`source.title` injection:</p>
<p>```javascript
source: {
  url: 'https://legit.example.com',
  title: '&lt;/source&gt;&lt;item&gt;&lt;title&gt;INJECTED&lt;/title&gt;&lt;link&gt;https://evil.com&lt;/link&gt;&lt;/item&gt;&lt;source&gt;',
}
// Result: RSS feed contains an injected &lt;item&gt; element with an evil.com link
```</p>
<p>`enclosure.type` injection:</p>
<p>```javascript…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8j5q-mfj2-5q9q"/>
  </entry>
</feed>
