<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:13:35 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-FV05780 — Security fixes in langfuse 3.213.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fv05780</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse&lt;/p&gt;
&lt;p&gt;Package langfuse version 3.213.0-r1 fixes 24 vulnerabilities: CVE-2026-59895, CVE-2026-59896, CVE-2026-59897, CVE-2026-69207, CVE-2026-71848...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse&lt;/p&gt;
&lt;p&gt;Package langfuse version 3.213.0-r1 fixes 24 vulnerabilities: CVE-2026-59895, CVE-2026-59896, CVE-2026-59897, CVE-2026-69207, CVE-2026-71848...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fv05780</guid>
    </item>
    <item>
      <title>EUVD-2026-334047</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-334047</link>
      <description>EUVD-2026-334047</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-334047</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59895</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59895</link>
      <description>&lt;p&gt;Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59895</guid>
    </item>
    <item>
      <title>GHSA-w62v-xxxg-mg59 — Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w62v-xxxg-mg59</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: hono&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`cx()` in `hono/css` composes class names from plain strings but marks the result as already-escaped without HTML-escaping the input. When the result is used as a JSX `class` attribute during server-side rendering, the value is written into the attribute unescaped, so untrusted input can break out of the `class` attribute and inject arbitrary markup, leading to Cross-Site Scripting (XSS).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Because the composed value is treated as pre-escaped, the HTML attribute escaping normally applied to interpolated values is skipped, and characters such as `&amp;#34;` pass through unescaped — allowing a value to terminate the attribute and add further attributes or elements. This arises when an application passes untrusted, user-controlled input as a class name to `cx()`, for example when merging a base class with an externally provided `className`.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;During server-side rendering, an attacker who controls a value passed to `cx()` can inject arbitrary HTML into the page, resulting in stored or reflected XSS in the victim&amp;#39;s browser.&lt;/p&gt;
&lt;p&gt;This may lead to:&lt;/p&gt;
&lt;p&gt;- Execution of attacker-controlled script in the victim&amp;#39;s browser session.
- Session hijacking, credential theft, or actions performed on behalf of the victim.&lt;/p&gt;
&lt;p&gt;Applications are affected only if they render JSX server-side and pass untrusted input as a class name to `cx()`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: hono&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`cx()` in `hono/css` composes class names from plain strings but marks the result as already-escaped without HTML-escaping the input. When the result is used as a JSX `class` attribute during server-side rendering, the value is written into the attribute unescaped, so untrusted input can break out of the `class` attribute and inject arbitrary markup, leading to Cross-Site Scripting (XSS).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Because the composed value is treated as pre-escaped, the HTML attribute escaping normally applied to interpolated values is skipped, and characters such as `&amp;#34;` pass through unescaped — allowing a value to terminate the attribute and add further attributes or elements. This arises when an application passes untrusted, user-controlled input as a class name to `cx()`, for example when merging a base class with an externally provided `className`.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;During server-side rendering, an attacker who controls a value passed to `cx()` can inject arbitrary HTML into the page, resulting in stored or reflected XSS in the victim&amp;#39;s browser.&lt;/p&gt;
&lt;p&gt;This may lead to:&lt;/p&gt;
&lt;p&gt;- Execution of attacker-controlled script in the victim&amp;#39;s browser session.
- Session hijacking, credential theft, or actions performed on behalf of the victim.&lt;/p&gt;
&lt;p&gt;Applications are affected only if they render JSX server-side and pass untrusted input as a class name to `cx()`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w62v-xxxg-mg59</guid>
    </item>
  </channel>
</rss>
