<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 12:33:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-10042</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-10042</link>
      <description>EUVD-2026-10042</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-10042</guid>
    </item>
    <item>
      <title>fkie_cve-2023-48699</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-48699</link>
      <description>&lt;p&gt;fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior to version 0.1.5, an attacker could modify the locators.ini locator file with python code that without proper validation it&amp;#39;s executed and it could lead to rce. The vulnerability is in the function `def __locator__(self, locator_name: str)` in `page.py`. In order to mitigate this issue, upgrade to fastbots version 0.1.5 or above.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior to version 0.1.5, an attacker could modify the locators.ini locator file with python code that without proper validation it&amp;#39;s executed and it could lead to rce. The vulnerability is in the function `def __locator__(self, locator_name: str)` in `page.py`. In order to mitigate this issue, upgrade to fastbots version 0.1.5 or above.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-48699</guid>
    </item>
    <item>
      <title>GHSA-vccg-f4gp-45x9 — Eval Injection in fastbots</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vccg-f4gp-45x9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: fastbots&lt;/p&gt;
&lt;p&gt;### Impact
An attacker could modify the locators.ini locator file with python code that without proper validation it&amp;#39;s executed and it could lead to rce. The vulnerability is in the function def __locator__(self, locator_name: str) in page.py. The vulnerable code that load and execute directly from the file without validation it&amp;#39;s:
```python
 return eval(self._bot.locator(self._page_name, locator_name))
```&lt;/p&gt;
&lt;p&gt;### Patches
In order to mitigate this issue it&amp;#39;s important to upgrade to fastbots version 0.1.5 or above.&lt;/p&gt;
&lt;p&gt;### References
[Merge that fix also this issue](https://github.com/ubertidavide/fastbots/pull/3#issue-2003080806)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: fastbots&lt;/p&gt;
&lt;p&gt;### Impact
An attacker could modify the locators.ini locator file with python code that without proper validation it&amp;#39;s executed and it could lead to rce. The vulnerability is in the function def __locator__(self, locator_name: str) in page.py. The vulnerable code that load and execute directly from the file without validation it&amp;#39;s:
```python
 return eval(self._bot.locator(self._page_name, locator_name))
```&lt;/p&gt;
&lt;p&gt;### Patches
In order to mitigate this issue it&amp;#39;s important to upgrade to fastbots version 0.1.5 or above.&lt;/p&gt;
&lt;p&gt;### References
[Merge that fix also this issue](https://github.com/ubertidavide/fastbots/pull/3#issue-2003080806)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vccg-f4gp-45x9</guid>
    </item>
    <item>
      <title>gsd-2023-48699</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-48699</link>
      <description>gsd-2023-48699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-48699</guid>
    </item>
  </channel>
</rss>
