<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:53:26 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-02353</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02353</link>
      <description>bdu:2026-02353</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02353</guid>
    </item>
    <item>
      <title>EUVD-2026-270969</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-270969</link>
      <description>EUVD-2026-270969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-270969</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25802</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25802</link>
      <description>&lt;p&gt;New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `&amp;lt;script&amp;gt;` tag. Version 0.10.8-alpha.9 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `&amp;lt;script&amp;gt;` tag. Version 0.10.8-alpha.9 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25802</guid>
    </item>
    <item>
      <title>GHSA-299v-8pq9-5gjq — New API has Potential XSS in its MarkdownRenderer component</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-299v-8pq9-5gjq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/QuantumNous/new-api&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `&amp;lt;script&amp;gt;` tag.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Line 212-231 of `MarkdownRenderer.jsx` is unsafe, it use dangerouslySetInnerHTML to preview html the model generates. This can trigger malcious scripts.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;A simple way to exploit that is to ask the model in the playground, with prompt: &amp;#34;请帮我写个脚本，跳转到google&amp;#34;, and then the browser will navigate to the google.com without user interference.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Potential malcious activity to the user using playground, if the model api is altered to output unintended codes.&lt;/p&gt;
&lt;p&gt;Also, users may not be easily rid the exploit, since the record of the chat containing XSS script is stored, once opening the page later, the script will be re-triggered.&lt;/p&gt;
&lt;p&gt;### Potential Workaround&lt;/p&gt;
&lt;p&gt;The preview may be placed in an iframe sandbox, dangerous html strings should be purified before rendering.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;The reply generated for test is as below:&lt;/p&gt;
&lt;p&gt;这是一个为您编写的单页 HTML 文件。它使用了两种方式来实现跳转，以确保在任何情况下都能工作：&lt;/p&gt;
&lt;p&gt;1.  **JavaScript (`window.location.replace`)**：这是最常用且高效的方法，它会立即跳转，并且不会保留当前页面在浏览器历史记录中（这样用户按“后退”键不会回到这个跳转页）。
2.  **HTML Meta Refresh**：作为后备方案。如果用户的浏览器禁用了 JavaScript，这个标签会在 1 秒后将用户带往 Google。
3.  **手动链接**：页面中显示了一个备用链接，以防自动跳转被拦截或失效。&lt;/p&gt;
&lt;p&gt;您可以直接保存以下代码为 `.html` 文件并在浏览器中打开。&lt;/p&gt;
&lt;p&gt;```html
&amp;lt;!DOCTYPE html&amp;gt;
&amp;lt;html lang=&amp;#34;zh-CN&amp;#34;&amp;gt;
&amp;lt;head&amp;gt;
    &amp;lt;meta charset=&amp;#34;UTF-8&amp;#34;&amp;gt;
    &amp;lt;meta name=&amp;#34;viewport&amp;#34; content=&amp;#34;width=device-width, initial-scale=1.0&amp;#34;&amp;gt;
    &amp;lt;titl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/QuantumNous/new-api&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `&amp;lt;script&amp;gt;` tag.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Line 212-231 of `MarkdownRenderer.jsx` is unsafe, it use dangerouslySetInnerHTML to preview html the model generates. This can trigger malcious scripts.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;A simple way to exploit that is to ask the model in the playground, with prompt: &amp;#34;请帮我写个脚本，跳转到google&amp;#34;, and then the browser will navigate to the google.com without user interference.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Potential malcious activity to the user using playground, if the model api is altered to output unintended codes.&lt;/p&gt;
&lt;p&gt;Also, users may not be easily rid the exploit, since the record of the chat containing XSS script is stored, once opening the page later, the script will be re-triggered.&lt;/p&gt;
&lt;p&gt;### Potential Workaround&lt;/p&gt;
&lt;p&gt;The preview may be placed in an iframe sandbox, dangerous html strings should be purified before rendering.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;The reply generated for test is as below:&lt;/p&gt;
&lt;p&gt;这是一个为您编写的单页 HTML 文件。它使用了两种方式来实现跳转，以确保在任何情况下都能工作：&lt;/p&gt;
&lt;p&gt;1.  **JavaScript (`window.location.replace`)**：这是最常用且高效的方法，它会立即跳转，并且不会保留当前页面在浏览器历史记录中（这样用户按“后退”键不会回到这个跳转页）。
2.  **HTML Meta Refresh**：作为后备方案。如果用户的浏览器禁用了 JavaScript，这个标签会在 1 秒后将用户带往 Google。
3.  **手动链接**：页面中显示了一个备用链接，以防自动跳转被拦截或失效。&lt;/p&gt;
&lt;p&gt;您可以直接保存以下代码为 `.html` 文件并在浏览器中打开。&lt;/p&gt;
&lt;p&gt;```html
&amp;lt;!DOCTYPE html&amp;gt;
&amp;lt;html lang=&amp;#34;zh-CN&amp;#34;&amp;gt;
&amp;lt;head&amp;gt;
    &amp;lt;meta charset=&amp;#34;UTF-8&amp;#34;&amp;gt;
    &amp;lt;meta name=&amp;#34;viewport&amp;#34; content=&amp;#34;width=device-width, initial-scale=1.0&amp;#34;&amp;gt;
    &amp;lt;titl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-299v-8pq9-5gjq</guid>
    </item>
  </channel>
</rss>
