<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 20:12:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-206295</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-206295</link>
      <description>EUVD-2026-206295</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-206295</guid>
    </item>
    <item>
      <title>fkie_cve-2024-54128</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-54128</link>
      <description>&lt;p&gt;Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML Injection. This vulerability is fixed in 10.13.4 and 11.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML Injection. This vulerability is fixed in 10.13.4 and 11.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-54128</guid>
    </item>
    <item>
      <title>GHSA-r6wx-627v-gh2f — Directus has an HTML Injection in Comment</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r6wx-627v-gh2f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @directus/app, npm: directus&lt;/p&gt;
&lt;p&gt;### Summary
The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML Injection.&lt;/p&gt;
&lt;p&gt;### Details
The Comment feature implements a character filter on the client-side, this can be bypassed by directly sending a request to the endpoint.&lt;/p&gt;
&lt;p&gt;Example Request:&lt;/p&gt;
&lt;p&gt;```
PATCH /activity/comment/3 HTTP/2
Host: directus.local&lt;/p&gt;
&lt;p&gt;{
  &amp;#34;comment&amp;#34;: &amp;#34;&amp;lt;h1&amp;gt;TEST &amp;lt;p style=\&amp;#34;color:red\&amp;#34;&amp;gt;HTML INJECTION&amp;lt;/p&amp;gt; &amp;lt;a href=\&amp;#34;//evil.com\&amp;#34;&amp;gt;Test Link&amp;lt;/a&amp;gt;&amp;lt;/h1&amp;gt;&amp;#34;
}
```&lt;/p&gt;
&lt;p&gt;Example Response:&lt;/p&gt;
&lt;p&gt;```json
{
  &amp;#34;data&amp;#34;: {
    &amp;#34;id&amp;#34;: 3,
    &amp;#34;action&amp;#34;: &amp;#34;comment&amp;#34;,
    &amp;#34;user&amp;#34;: &amp;#34;288fdccc-399a-40a1-ac63-811bf62e6a18&amp;#34;,
    &amp;#34;timestamp&amp;#34;: &amp;#34;2023-09-06T02:23:40.740Z&amp;#34;,
    &amp;#34;ip&amp;#34;: &amp;#34;10.42.0.1&amp;#34;,
    &amp;#34;user_agent&amp;#34;: &amp;#34;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36&amp;#34;,
    &amp;#34;collection&amp;#34;: &amp;#34;directus_files&amp;#34;,
    &amp;#34;item&amp;#34;: &amp;#34;7247dda1-c386-4e7a-8121-7e9c1a42c15a&amp;#34;,
    &amp;#34;comment&amp;#34;: &amp;#34;&amp;lt;h1&amp;gt;TEST &amp;lt;p style=\&amp;#34;color:red\&amp;#34;&amp;gt;HTML INJECTION&amp;lt;/p&amp;gt; &amp;lt;a href=\&amp;#34;//evil.com\&amp;#34;&amp;gt;Test Link&amp;lt;/a&amp;gt;&amp;lt;/h1&amp;gt;&amp;#34;,
    &amp;#34;origin&amp;#34;: &amp;#34;https://directus.local&amp;#34;,
    &amp;#34;revisions&amp;#34;: []
  }
}
```&lt;/p&gt;
&lt;p&gt;Example Result:&lt;/p&gt;
&lt;p&gt;![Screenshot 2023-09-06 094536](https://user-images.githubusercontent.com/61263002/265876100-12e068fe-3d53-41b4-bfcb-458c2bc2a638.png)&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;With the introduction of session cookies this issue has become exploitable as a malicious script is now able to do authenticated acti…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @directus/app, npm: directus&lt;/p&gt;
&lt;p&gt;### Summary
The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML Injection.&lt;/p&gt;
&lt;p&gt;### Details
The Comment feature implements a character filter on the client-side, this can be bypassed by directly sending a request to the endpoint.&lt;/p&gt;
&lt;p&gt;Example Request:&lt;/p&gt;
&lt;p&gt;```
PATCH /activity/comment/3 HTTP/2
Host: directus.local&lt;/p&gt;
&lt;p&gt;{
  &amp;#34;comment&amp;#34;: &amp;#34;&amp;lt;h1&amp;gt;TEST &amp;lt;p style=\&amp;#34;color:red\&amp;#34;&amp;gt;HTML INJECTION&amp;lt;/p&amp;gt; &amp;lt;a href=\&amp;#34;//evil.com\&amp;#34;&amp;gt;Test Link&amp;lt;/a&amp;gt;&amp;lt;/h1&amp;gt;&amp;#34;
}
```&lt;/p&gt;
&lt;p&gt;Example Response:&lt;/p&gt;
&lt;p&gt;```json
{
  &amp;#34;data&amp;#34;: {
    &amp;#34;id&amp;#34;: 3,
    &amp;#34;action&amp;#34;: &amp;#34;comment&amp;#34;,
    &amp;#34;user&amp;#34;: &amp;#34;288fdccc-399a-40a1-ac63-811bf62e6a18&amp;#34;,
    &amp;#34;timestamp&amp;#34;: &amp;#34;2023-09-06T02:23:40.740Z&amp;#34;,
    &amp;#34;ip&amp;#34;: &amp;#34;10.42.0.1&amp;#34;,
    &amp;#34;user_agent&amp;#34;: &amp;#34;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36&amp;#34;,
    &amp;#34;collection&amp;#34;: &amp;#34;directus_files&amp;#34;,
    &amp;#34;item&amp;#34;: &amp;#34;7247dda1-c386-4e7a-8121-7e9c1a42c15a&amp;#34;,
    &amp;#34;comment&amp;#34;: &amp;#34;&amp;lt;h1&amp;gt;TEST &amp;lt;p style=\&amp;#34;color:red\&amp;#34;&amp;gt;HTML INJECTION&amp;lt;/p&amp;gt; &amp;lt;a href=\&amp;#34;//evil.com\&amp;#34;&amp;gt;Test Link&amp;lt;/a&amp;gt;&amp;lt;/h1&amp;gt;&amp;#34;,
    &amp;#34;origin&amp;#34;: &amp;#34;https://directus.local&amp;#34;,
    &amp;#34;revisions&amp;#34;: []
  }
}
```&lt;/p&gt;
&lt;p&gt;Example Result:&lt;/p&gt;
&lt;p&gt;![Screenshot 2023-09-06 094536](https://user-images.githubusercontent.com/61263002/265876100-12e068fe-3d53-41b4-bfcb-458c2bc2a638.png)&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;With the introduction of session cookies this issue has become exploitable as a malicious script is now able to do authenticated acti…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r6wx-627v-gh2f</guid>
    </item>
  </channel>
</rss>
