<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:08:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-217342</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217342</link>
      <description>EUVD-2026-217342</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217342</guid>
    </item>
    <item>
      <title>fkie_cve-2024-27285</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27285</link>
      <description>&lt;p&gt;YARD is a Ruby Documentation tool. The &amp;#34;frames.html&amp;#34; file within the Yard Doc&amp;#39;s generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the &amp;#34;frames.erb&amp;#34; template file.  This vulnerability is fixed in 0.9.36.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;YARD is a Ruby Documentation tool. The &amp;#34;frames.html&amp;#34; file within the Yard Doc&amp;#39;s generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the &amp;#34;frames.erb&amp;#34; template file.  This vulnerability is fixed in 0.9.36.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-27285</guid>
    </item>
    <item>
      <title>GHSA-8mq4-9jjh-9xrc — YARD's default template vulnerable to Cross-site Scripting in generated frames.html</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8mq4-9jjh-9xrc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: yard&lt;/p&gt;
&lt;p&gt;### Summary
The &amp;#34;frames.html&amp;#34; file within the Yard Doc&amp;#39;s generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the &amp;#34;frames.erb&amp;#34; template file.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the &amp;#34;frames.erb&amp;#34; template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window&amp;#39;s location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs.&lt;/p&gt;
&lt;p&gt;Snippet from &amp;#34;frames.erb&amp;#34;:
(v0.9.34)
```erb
&amp;lt;script type=&amp;#34;text/javascript&amp;#34;&amp;gt;
  var match = unescape(window.location.hash).match(/^#!(.+)/);
  var name = match ? match[1] : &amp;#39;&amp;lt;%= url_for_main %&amp;gt;&amp;#39;;
  name = name.replace(/^(\w+):\/\//, &amp;#39;&amp;#39;).replace(/^\/\//, &amp;#39;&amp;#39;);
  window.top.location = name;
&amp;lt;/script&amp;gt;
```&lt;/p&gt;
&lt;p&gt;(v0.9.35)
```erb
&amp;lt;script type=&amp;#34;text/javascript&amp;#34;&amp;gt;
  var match = decodeURIComponent(window.location.hash).match(/^#!(.+)/);
  var name = match ? match[1] : &amp;#39;&amp;lt;%= url_for_main %&amp;gt;&amp;#39;;
  name = name.replace(/^((\w*):)?[\/\\]*/gm, &amp;#39;&amp;#39;).trim();
  window.top.location.replace(name)
&amp;lt;/script&amp;gt;
```&lt;/p&gt;
&lt;p&gt;### PoC (Proof of Concept)
To exploit this vulnerability:
1. Gain access to the generated Yard Doc.
2. Locate and access the &amp;#34;frames.html&amp;#34; file.
3. Construct a URL containing the malicious payload in the hash segment, for instance: `#!javascript:xss` fo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: yard&lt;/p&gt;
&lt;p&gt;### Summary
The &amp;#34;frames.html&amp;#34; file within the Yard Doc&amp;#39;s generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the &amp;#34;frames.erb&amp;#34; template file.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the &amp;#34;frames.erb&amp;#34; template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window&amp;#39;s location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs.&lt;/p&gt;
&lt;p&gt;Snippet from &amp;#34;frames.erb&amp;#34;:
(v0.9.34)
```erb
&amp;lt;script type=&amp;#34;text/javascript&amp;#34;&amp;gt;
  var match = unescape(window.location.hash).match(/^#!(.+)/);
  var name = match ? match[1] : &amp;#39;&amp;lt;%= url_for_main %&amp;gt;&amp;#39;;
  name = name.replace(/^(\w+):\/\//, &amp;#39;&amp;#39;).replace(/^\/\//, &amp;#39;&amp;#39;);
  window.top.location = name;
&amp;lt;/script&amp;gt;
```&lt;/p&gt;
&lt;p&gt;(v0.9.35)
```erb
&amp;lt;script type=&amp;#34;text/javascript&amp;#34;&amp;gt;
  var match = decodeURIComponent(window.location.hash).match(/^#!(.+)/);
  var name = match ? match[1] : &amp;#39;&amp;lt;%= url_for_main %&amp;gt;&amp;#39;;
  name = name.replace(/^((\w*):)?[\/\\]*/gm, &amp;#39;&amp;#39;).trim();
  window.top.location.replace(name)
&amp;lt;/script&amp;gt;
```&lt;/p&gt;
&lt;p&gt;### PoC (Proof of Concept)
To exploit this vulnerability:
1. Gain access to the generated Yard Doc.
2. Locate and access the &amp;#34;frames.html&amp;#34; file.
3. Construct a URL containing the malicious payload in the hash segment, for instance: `#!javascript:xss` fo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8mq4-9jjh-9xrc</guid>
    </item>
    <item>
      <title>gsd-2024-27285</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-27285</link>
      <description>gsd-2024-27285</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-27285</guid>
    </item>
    <item>
      <title>OESA-2024-1256 — rubygem-yard security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1256</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-yard, openEuler:20.03-LTS-SP4: rubygem-yard, openEuler:22.03-LTS: rubygem-yard, openEuler:22.03-LTS-SP1: rubygem-yard, openEuler:22.03-LTS-SP2: rubygem-yard, openEuler:22.03-LTS-SP3: rubygem-yard&lt;/p&gt;
&lt;p&gt;YARD is a documentation generation tool for the Ruby programming language. It enables the user to generate consistent, usable documentation that can be exported to a number of formats very easily, and also supports extending for custom Ruby constructs such as custom class level definitions.&#13;
&#13;
Security Fix(es):&#13;
&#13;
YARD is a Ruby Documentation tool. The &amp;amp;quot;frames.html&amp;amp;quot; file within the Yard Doc&amp;amp;apos;s generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the &amp;amp;quot;frames.erb&amp;amp;quot; template file.  This vulnerability is fixed in 0.9.36.(CVE-2024-27285)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-yard, openEuler:20.03-LTS-SP4: rubygem-yard, openEuler:22.03-LTS: rubygem-yard, openEuler:22.03-LTS-SP1: rubygem-yard, openEuler:22.03-LTS-SP2: rubygem-yard, openEuler:22.03-LTS-SP3: rubygem-yard&lt;/p&gt;
&lt;p&gt;YARD is a documentation generation tool for the Ruby programming language. It enables the user to generate consistent, usable documentation that can be exported to a number of formats very easily, and also supports extending for custom Ruby constructs such as custom class level definitions.&#13;
&#13;
Security Fix(es):&#13;
&#13;
YARD is a Ruby Documentation tool. The &amp;amp;quot;frames.html&amp;amp;quot; file within the Yard Doc&amp;amp;apos;s generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the &amp;amp;quot;frames.erb&amp;amp;quot; template file.  This vulnerability is fixed in 0.9.36.(CVE-2024-27285)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1256</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-27285</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27285</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: yard, Ubuntu:Pro:18.04:LTS: yard, Ubuntu:20.04:LTS: yard, Ubuntu:22.04:LTS: yard&lt;/p&gt;
&lt;p&gt;YARD is a Ruby Documentation tool. The &amp;#34;frames.html&amp;#34; file within the Yard Doc&amp;#39;s generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the &amp;#34;frames.erb&amp;#34; template file.  This vulnerability is fixed in 0.9.36.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: yard, Ubuntu:Pro:18.04:LTS: yard, Ubuntu:20.04:LTS: yard, Ubuntu:22.04:LTS: yard&lt;/p&gt;
&lt;p&gt;YARD is a Ruby Documentation tool. The &amp;#34;frames.html&amp;#34; file within the Yard Doc&amp;#39;s generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the &amp;#34;frames.erb&amp;#34; template file.  This vulnerability is fixed in 0.9.36.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27285</guid>
    </item>
  </channel>
</rss>
