<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:50:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-244726</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-244726</link>
      <description>EUVD-2026-244726</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-244726</guid>
    </item>
    <item>
      <title>fkie_cve-2024-21636</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-21636</link>
      <description>&lt;p&gt;view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. Versions prior to 3.9.0 and 2.83.0 have a cross-site scripting vulnerability that has the potential to impact anyone rendering a component directly from a controller with the view_component gem. Note that only components that define a `#call` method (i.e. instead of using a sidecar template) are affected. The return value of the `#call` method is not sanitized and can include user-defined content. In addition, the return value of the `#output_postamble` methodis not sanitized, which can also lead to cross-site scripting issues. Versions 3.9.0 and 2.83.0 have been released and fully mitigate both the `#call` and the `#output_postamble` vulnerabilities. As a workaround, sanitize the return value of `#call`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. Versions prior to 3.9.0 and 2.83.0 have a cross-site scripting vulnerability that has the potential to impact anyone rendering a component directly from a controller with the view_component gem. Note that only components that define a `#call` method (i.e. instead of using a sidecar template) are affected. The return value of the `#call` method is not sanitized and can include user-defined content. In addition, the return value of the `#output_postamble` methodis not sanitized, which can also lead to cross-site scripting issues. Versions 3.9.0 and 2.83.0 have been released and fully mitigate both the `#call` and the `#output_postamble` vulnerabilities. As a workaround, sanitize the return value of `#call`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-21636</guid>
    </item>
    <item>
      <title>GHSA-wf2x-8w6j-qw37 — view_component Cross-site Scripting vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wf2x-8w6j-qw37</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: view_component&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;This is an XSS vulnerability that has the potential to impact anyone rendering a component directly from a controller with the view_component gem. Note that only components that define a [`#call` method](https://viewcomponent.org/guide/templates.html#call) (i.e. instead of using a sidecar template) are affected. The return value of the `#call` method is not sanitized and can include user-defined content.&lt;/p&gt;
&lt;p&gt;In addition, the return value of the [`#output_postamble` method](https://viewcomponent.org/api.html#output_postamble--string) is not sanitized, which can also lead to XSS issues.&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;Versions 3.9.0 has been released and fully mitigates both the `#call` and the `#output_postamble` vulnerabilities.&lt;/p&gt;
&lt;p&gt;### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;Sanitize the return value of `#call`, eg:&lt;/p&gt;
&lt;p&gt;```ruby
class MyComponent &amp;lt; ApplicationComponent
  def call
    html_escape(&amp;#34;&amp;lt;div&amp;gt;#{user_input}&amp;lt;/div&amp;gt;&amp;#34;)
  end
end
```&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_&lt;/p&gt;
&lt;p&gt;https://github.com/ViewComponent/view_component/pull/1950&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;Open an issue in the [github/view_component](https://github.com/github/view_component) project.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: view_component&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;This is an XSS vulnerability that has the potential to impact anyone rendering a component directly from a controller with the view_component gem. Note that only components that define a [`#call` method](https://viewcomponent.org/guide/templates.html#call) (i.e. instead of using a sidecar template) are affected. The return value of the `#call` method is not sanitized and can include user-defined content.&lt;/p&gt;
&lt;p&gt;In addition, the return value of the [`#output_postamble` method](https://viewcomponent.org/api.html#output_postamble--string) is not sanitized, which can also lead to XSS issues.&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;Versions 3.9.0 has been released and fully mitigates both the `#call` and the `#output_postamble` vulnerabilities.&lt;/p&gt;
&lt;p&gt;### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;Sanitize the return value of `#call`, eg:&lt;/p&gt;
&lt;p&gt;```ruby
class MyComponent &amp;lt; ApplicationComponent
  def call
    html_escape(&amp;#34;&amp;lt;div&amp;gt;#{user_input}&amp;lt;/div&amp;gt;&amp;#34;)
  end
end
```&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_&lt;/p&gt;
&lt;p&gt;https://github.com/ViewComponent/view_component/pull/1950&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;Open an issue in the [github/view_component](https://github.com/github/view_component) project.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wf2x-8w6j-qw37</guid>
    </item>
    <item>
      <title>gsd-2024-21636</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-21636</link>
      <description>gsd-2024-21636</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-21636</guid>
    </item>
  </channel>
</rss>
