<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:46:54 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-53382</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-53382</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PrismJS Prism&lt;/p&gt;
&lt;p&gt;Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PrismJS Prism&lt;/p&gt;
&lt;p&gt;Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-53382</guid>
    </item>
    <item>
      <title>GHSA-c7w3-x93f-qmm8 — Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c7w3-x93f-qmm8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nodemailer&lt;/p&gt;
&lt;p&gt;### Summary
When a custom `envelope` object is passed to `sendMail()` with a `size` property containing CRLF characters (`\r\n`), the value is concatenated directly into the SMTP `MAIL FROM` command without sanitization. This allows injection of arbitrary SMTP commands, including `RCPT TO` — silently adding attacker-controlled recipients to outgoing emails.&lt;/p&gt;
&lt;p&gt;### Details
In `lib/smtp-connection/index.js` (lines 1161-1162), the `envelope.size` value is concatenated into the SMTP `MAIL FROM` command without any CRLF sanitization:&lt;/p&gt;
&lt;p&gt;```javascript
if (this._envelope.size &amp;amp;&amp;amp; this._supportedExtensions.includes(&amp;#39;SIZE&amp;#39;)) {
    args.push(&amp;#39;SIZE=&amp;#39; + this._envelope.size);
}
```&lt;/p&gt;
&lt;p&gt;This contrasts with other envelope parameters in the same function that ARE properly sanitized:
- **Addresses** (`from`, `to`): validated for `[\r\n&amp;lt;&amp;gt;]` at lines 1107-1127
- **DSN parameters** (`dsn.ret`, `dsn.envid`, `dsn.orcpt`): encoded via `encodeXText()` at lines 1167-1183&lt;/p&gt;
&lt;p&gt;The `size` property reaches this code path through `MimeNode.setEnvelope()` in `lib/mime-node/index.js` (lines 854-858), which copies all non-standard envelope properties verbatim:&lt;/p&gt;
&lt;p&gt;```javascript
const standardFields = [&amp;#39;to&amp;#39;, &amp;#39;cc&amp;#39;, &amp;#39;bcc&amp;#39;, &amp;#39;from&amp;#39;];
Object.keys(envelope).forEach(key =&amp;gt; {
    if (!standardFields.includes(key)) {
        this._envelope[key] = envelope[key];
    }
});
```&lt;/p&gt;
&lt;p&gt;Since `_sendCommand()` writes the command string followed by `\r\n` to the raw TCP socket, a CRLF in the `size` value terminates the `MAIL FROM` command and…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nodemailer&lt;/p&gt;
&lt;p&gt;### Summary
When a custom `envelope` object is passed to `sendMail()` with a `size` property containing CRLF characters (`\r\n`), the value is concatenated directly into the SMTP `MAIL FROM` command without sanitization. This allows injection of arbitrary SMTP commands, including `RCPT TO` — silently adding attacker-controlled recipients to outgoing emails.&lt;/p&gt;
&lt;p&gt;### Details
In `lib/smtp-connection/index.js` (lines 1161-1162), the `envelope.size` value is concatenated into the SMTP `MAIL FROM` command without any CRLF sanitization:&lt;/p&gt;
&lt;p&gt;```javascript
if (this._envelope.size &amp;amp;&amp;amp; this._supportedExtensions.includes(&amp;#39;SIZE&amp;#39;)) {
    args.push(&amp;#39;SIZE=&amp;#39; + this._envelope.size);
}
```&lt;/p&gt;
&lt;p&gt;This contrasts with other envelope parameters in the same function that ARE properly sanitized:
- **Addresses** (`from`, `to`): validated for `[\r\n&amp;lt;&amp;gt;]` at lines 1107-1127
- **DSN parameters** (`dsn.ret`, `dsn.envid`, `dsn.orcpt`): encoded via `encodeXText()` at lines 1167-1183&lt;/p&gt;
&lt;p&gt;The `size` property reaches this code path through `MimeNode.setEnvelope()` in `lib/mime-node/index.js` (lines 854-858), which copies all non-standard envelope properties verbatim:&lt;/p&gt;
&lt;p&gt;```javascript
const standardFields = [&amp;#39;to&amp;#39;, &amp;#39;cc&amp;#39;, &amp;#39;bcc&amp;#39;, &amp;#39;from&amp;#39;];
Object.keys(envelope).forEach(key =&amp;gt; {
    if (!standardFields.includes(key)) {
        this._envelope[key] = envelope[key];
    }
});
```&lt;/p&gt;
&lt;p&gt;Since `_sendCommand()` writes the command string followed by `\r\n` to the raw TCP socket, a CRLF in the `size` value terminates the `MAIL FROM` command and…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c7w3-x93f-qmm8</guid>
    </item>
  </channel>
</rss>
