<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 22:04:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-262278</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262278</link>
      <description>EUVD-2026-262278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262278</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66400</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66400</link>
      <description>&lt;p&gt;mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in 13.2.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in 13.2.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66400</guid>
    </item>
    <item>
      <title>GHSA-4fh9-h7wg-q85m — mdast-util-to-hast has unsanitized class attribute</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4fh9-h7wg-q85m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mdast-util-to-hast&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Multiple (unprefixed) classnames could be added in markdown source by using character references.
This could make rendered user supplied markdown `code` elements appear like the rest of the page.
The following markdown:&lt;/p&gt;
&lt;p&gt;````markdown
```js&amp;amp;#x20;xss
```
````&lt;/p&gt;
&lt;p&gt;Would create `&amp;lt;pre&amp;gt;&amp;lt;code class=&amp;#34;language-js xss&amp;#34;&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;`
If your page then applied `.xss` classes (or listeners in JS), those apply to this element.
For more info see &amp;lt;https://github.com/ChALkeR/notes/blob/master/Improper-markup-sanitization.md#unsanitized-class-attribute&amp;gt;&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The bug was patched. When using regular semver, run `npm install`. For exact ranges, make sure to use `13.2.1`.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Update.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* bug introduced in https://github.com/syntax-tree/mdast-util-to-hast/commit/6fc783ae6abdeb798fd5a68e7f3f21411dde7403
* bug fixed in https://github.com/syntax-tree/mdast-util-to-hast/commit/ab3a79570a1afbfa7efef5d4a0cd9b5caafbc5d7&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mdast-util-to-hast&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Multiple (unprefixed) classnames could be added in markdown source by using character references.
This could make rendered user supplied markdown `code` elements appear like the rest of the page.
The following markdown:&lt;/p&gt;
&lt;p&gt;````markdown
```js&amp;amp;#x20;xss
```
````&lt;/p&gt;
&lt;p&gt;Would create `&amp;lt;pre&amp;gt;&amp;lt;code class=&amp;#34;language-js xss&amp;#34;&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;`
If your page then applied `.xss` classes (or listeners in JS), those apply to this element.
For more info see &amp;lt;https://github.com/ChALkeR/notes/blob/master/Improper-markup-sanitization.md#unsanitized-class-attribute&amp;gt;&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The bug was patched. When using regular semver, run `npm install`. For exact ranges, make sure to use `13.2.1`.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Update.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* bug introduced in https://github.com/syntax-tree/mdast-util-to-hast/commit/6fc783ae6abdeb798fd5a68e7f3f21411dde7403
* bug fixed in https://github.com/syntax-tree/mdast-util-to-hast/commit/ab3a79570a1afbfa7efef5d4a0cd9b5caafbc5d7&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4fh9-h7wg-q85m</guid>
    </item>
  </channel>
</rss>
