<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 00:55:53 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-7042 — Prompt Injection in langchain-ai/langchainjs Leading to SQL Injection</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-7042</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; langchain-ai/langchainjs, langchain-ai langchainjs&lt;/p&gt;
&lt;p&gt;A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; langchain-ai/langchainjs, langchain-ai langchainjs&lt;/p&gt;
&lt;p&gt;A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-7042</guid>
    </item>
    <item>
      <title>GHSA-42h9-826w-cgv3 — Axios: Excessive recursion in formDataToJSON can cause denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-42h9-826w-cgv3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary
Axios versions `0.28.0` and later contain uncontrolled recursion in `formDataToJSON`, the helper behind the public `axios.formToJSON()` / named `formToJSON` API and the default request transform used when FormData is sent with an `application/json` content type.&lt;/p&gt;
&lt;p&gt;Applications are affected when they pass attacker-controlled `FormData` field names into this functionality. A field name with thousands of nested bracket segments can exhaust the JavaScript call stack and throw `RangeError: Maximum call stack size exceeded`, causing request failure and, in applications that do not handle the exception or rejected promise, possible process termination.&lt;/p&gt;
&lt;p&gt;## Impact
The impact is denial of service against applications that process untrusted `FormData` field names through axios&amp;#39; FormData-to-JSON conversion.&lt;/p&gt;
&lt;p&gt;The vulnerable path is not reached by merely installing axios, by normal multipart `FormData` pass-through, or by ordinary axios requests that do not request JSON serialisation of `FormData`. In the default axios request, the error is produced before network I/O and returned as a rejected Promise. Direct use of `formToJSON()` throws synchronously.&lt;/p&gt;
&lt;p&gt;Server-side applications are the primary risk when remote users can submit arbitrary form field names, and the application converts those fields with `formToJSON()` or sends them through axios as JSON.&lt;/p&gt;
&lt;p&gt;## Affected Functionality
Affected APIs and paths:
- `axios.formToJSON(formData)`
- `import { formToJSON } from &amp;#34;axios&amp;#34;`
- `li…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary
Axios versions `0.28.0` and later contain uncontrolled recursion in `formDataToJSON`, the helper behind the public `axios.formToJSON()` / named `formToJSON` API and the default request transform used when FormData is sent with an `application/json` content type.&lt;/p&gt;
&lt;p&gt;Applications are affected when they pass attacker-controlled `FormData` field names into this functionality. A field name with thousands of nested bracket segments can exhaust the JavaScript call stack and throw `RangeError: Maximum call stack size exceeded`, causing request failure and, in applications that do not handle the exception or rejected promise, possible process termination.&lt;/p&gt;
&lt;p&gt;## Impact
The impact is denial of service against applications that process untrusted `FormData` field names through axios&amp;#39; FormData-to-JSON conversion.&lt;/p&gt;
&lt;p&gt;The vulnerable path is not reached by merely installing axios, by normal multipart `FormData` pass-through, or by ordinary axios requests that do not request JSON serialisation of `FormData`. In the default axios request, the error is produced before network I/O and returned as a rejected Promise. Direct use of `formToJSON()` throws synchronously.&lt;/p&gt;
&lt;p&gt;Server-side applications are the primary risk when remote users can submit arbitrary form field names, and the application converts those fields with `formToJSON()` or sends them through axios as JSON.&lt;/p&gt;
&lt;p&gt;## Affected Functionality
Affected APIs and paths:
- `axios.formToJSON(formData)`
- `import { formToJSON } from &amp;#34;axios&amp;#34;`
- `li…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-42h9-826w-cgv3</guid>
    </item>
  </channel>
</rss>
