<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:22:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-331649</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331649</link>
      <description>EUVD-2026-331649</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331649</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56356</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56356</link>
      <description>&lt;p&gt;n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node&amp;#39;s Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.14.0 (fixed in 1.123.27, 2.13.3, and 2.14.1). An authenticated user with permission to create or modify workflows can inject JavaScript that bypasses sanitization, resulting in stored XSS against any user who visits the public chat page.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node&amp;#39;s Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.14.0 (fixed in 1.123.27, 2.13.3, and 2.14.1). An authenticated user with permission to create or modify workflows can inject JavaScript that bypasses sanitization, resulting in stored XSS against any user who visits the public chat page.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56356</guid>
    </item>
    <item>
      <title>GHSA-99wx-hwrx-8g4w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-99wx-hwrx-8g4w</link>
      <description>&lt;p&gt;n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node&amp;#39;s Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.14.0 (fixed in 1.123.27, 2.13.3, and 2.14.1). An authenticated user with permission to create or modify workflows can inject JavaScript that bypasses sanitization, resulting in stored XSS against any user who visits the public chat page.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node&amp;#39;s Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.14.0 (fixed in 1.123.27, 2.13.3, and 2.14.1). An authenticated user with permission to create or modify workflows can inject JavaScript that bypasses sanitization, resulting in stored XSS against any user who visits the public chat page.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-99wx-hwrx-8g4w</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0877 — n8n: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0877</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in n8n ausnutzen, um erweiterte Privilegien, einschließlich Administratorrechte, zu erlangen, um beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder Cross-Site- und Man-in-the-Middle-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in n8n ausnutzen, um erweiterte Privilegien, einschließlich Administratorrechte, zu erlangen, um beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder Cross-Site- und Man-in-the-Middle-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0877</guid>
    </item>
  </channel>
</rss>
