<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:41:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-232588</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232588</link>
      <description>EUVD-2026-232588</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232588</guid>
    </item>
    <item>
      <title>fkie_cve-2022-39322</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39322</link>
      <description>&lt;p&gt;@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if configured - are vulnerable to their field-level access control not being used. List-level access control is not affected. Field-level access control for fields other than `multiselect` are not affected. Version 2.3.1 contains a fix for this issue. As a workaround, stop using the `multiselect` field.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if configured - are vulnerable to their field-level access control not being used. List-level access control is not affected. Field-level access control for fields other than `multiselect` are not affected. Version 2.3.1 contains a fix for this issue. As a workaround, stop using the `multiselect` field.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-39322</guid>
    </item>
    <item>
      <title>GHSA-6mhr-52mv-6v6f — Field-level access-control bypass for multiselect field</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6mhr-52mv-6v6f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @keystone-6/core&lt;/p&gt;
&lt;p&gt;#### Impact&lt;/p&gt;
&lt;p&gt;`@keystone-6/core@2.2.0 || 2.3.0` users who are using the `multiselect` field, and provided field-level access control - are vulnerable to their field-level access control not being used.&lt;/p&gt;
&lt;p&gt;List-level access control is **NOT** affected.&lt;/p&gt;
&lt;p&gt;Field-level access control for fields other than `multiselect` are **NOT** affected.&lt;/p&gt;
&lt;p&gt;Example, **you are vulnerable if** you are using field-level access control on a `multiselect` like the following:
```ts
const yourList = list({
  access: {
    // this is list-level access control, this is NOT impacted
  },
  fields: {
    yourFieldName: multiselect({
      // this is field-level access control, for multiselect fields
      //   this is vulnerable
      access: {
        create: ({ session }) =&amp;gt; session?.data.isAdmin,
        update: ({ session }) =&amp;gt; session?.data.isAdmin,
      },
      options: [
        { value: &amp;#39;apples&amp;#39;, label: &amp;#39;Apples&amp;#39; },
        { value: &amp;#39;oranges&amp;#39;, label: &amp;#39;Oranges&amp;#39; },
      ],
      // ...
    }),
    // ...
  },
  // ...
});
```&lt;/p&gt;
&lt;p&gt;#### Mitigation
Please upgrade to `@keystone-6/core &amp;gt;= 2.3.1`, where this vulnerability has been closed.&lt;/p&gt;
&lt;p&gt;#### Workarounds
If for some reason you cannot upgrade your dependencies, you should stop using the `multiselect` field.&lt;/p&gt;
&lt;p&gt;#### Credits
Thanks to [Marek R](https://github.com/marekryb) for reporting and submitting the pull request to fix this problem.&lt;/p&gt;
&lt;p&gt;If you have any questions around this security advisory, please don&amp;#39;t hesitate to contact us at [security@keystonejs.com](mai…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @keystone-6/core&lt;/p&gt;
&lt;p&gt;#### Impact&lt;/p&gt;
&lt;p&gt;`@keystone-6/core@2.2.0 || 2.3.0` users who are using the `multiselect` field, and provided field-level access control - are vulnerable to their field-level access control not being used.&lt;/p&gt;
&lt;p&gt;List-level access control is **NOT** affected.&lt;/p&gt;
&lt;p&gt;Field-level access control for fields other than `multiselect` are **NOT** affected.&lt;/p&gt;
&lt;p&gt;Example, **you are vulnerable if** you are using field-level access control on a `multiselect` like the following:
```ts
const yourList = list({
  access: {
    // this is list-level access control, this is NOT impacted
  },
  fields: {
    yourFieldName: multiselect({
      // this is field-level access control, for multiselect fields
      //   this is vulnerable
      access: {
        create: ({ session }) =&amp;gt; session?.data.isAdmin,
        update: ({ session }) =&amp;gt; session?.data.isAdmin,
      },
      options: [
        { value: &amp;#39;apples&amp;#39;, label: &amp;#39;Apples&amp;#39; },
        { value: &amp;#39;oranges&amp;#39;, label: &amp;#39;Oranges&amp;#39; },
      ],
      // ...
    }),
    // ...
  },
  // ...
});
```&lt;/p&gt;
&lt;p&gt;#### Mitigation
Please upgrade to `@keystone-6/core &amp;gt;= 2.3.1`, where this vulnerability has been closed.&lt;/p&gt;
&lt;p&gt;#### Workarounds
If for some reason you cannot upgrade your dependencies, you should stop using the `multiselect` field.&lt;/p&gt;
&lt;p&gt;#### Credits
Thanks to [Marek R](https://github.com/marekryb) for reporting and submitting the pull request to fix this problem.&lt;/p&gt;
&lt;p&gt;If you have any questions around this security advisory, please don&amp;#39;t hesitate to contact us at [security@keystonejs.com](mai…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6mhr-52mv-6v6f</guid>
    </item>
    <item>
      <title>gsd-2022-39322</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-39322</link>
      <description>gsd-2022-39322</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-39322</guid>
    </item>
  </channel>
</rss>
