<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T11:16:12.284743+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352533</id>
    <title>EUVD-2026-352533</title>
    <updated>2026-10-10T11:16:12.330342+00:00</updated>
    <content>EUVD-2026-352533</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352533"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73649</id>
    <title>fkie_cve-2026-73649</title>
    <updated>2026-10-10T11:16:12.330377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts remained unfiltered. The getReferences() flow called getAttributes(), whose property access allowed an attacker-controlled template to traverse constructor.constructor to the JavaScript Function constructor. The #set handler validated only the assignment target and did not inspect the right-hand property-read expression, allowing arbitrary shell commands, environment-variable access, cloud-credential access, and internal-network access in the server process. This issue is fixed in version 2.1.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73649"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7gfh-x38p-prh3</id>
    <title>GHSA-7gfh-x38p-prh3 — Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)</title>
    <updated>2026-10-10T11:16:12.330414+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: velocityjs</p>
<p>### Summary</p>
<p>Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq ("Prototype Pollution in #set path assignment") — that advisory blocked constructor/__proto__/prototype only in the #set assignment handler (set.cjs), but property read expressions are unfiltered. Any application rendering attacker-controlled Velocity templates is vulnerable to arbitrary code execution on the server.</p>
<p>### Details</p>
<p>GHSA-j658-c2gf-x6pq added isBlockedPathKey() to dist/cjs/compile/set.cjs:35-43, which blocks __proto__, constructor, and prototype keys. However, this check only runs when the #set directive assigns a value — it validates the assignment target path, not the value expression being evaluated.
The value expression is evaluated via getReferences() in dist/cjs/compile/references.cjs:16, which calls getAttributes() at line 81. The property access at line 88-89 has no filtering:
// references.cjs:81-91
getAttributes(property, baseRef, ast) {
  if (property.type === "property") {
    return baseRef[property.id];  // ← NO BLOCK on "constructor", "prototype", etc.
  }
  ...
}
Meanwhile, set.cjs:35-43 properly blocks these keys, but only for the #set target:
// set.cjs:35-43
isBlockedPathKey(baseRef, key, isEnd) {
  if (key === PROTO_KEY) return true;          // "__proto__"
  if (key === "prototype" &amp;&amp; typeof baseRef === "function") return true;
  return !isEnd &amp;&amp; PROTOTYPE_CHAIN_KEYS.has(key) &amp;&amp; !hasOwnPr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7gfh-x38p-prh3"/>
  </entry>
</feed>
