<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 06:48:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-319767</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319767</link>
      <description>EUVD-2026-319767</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319767</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26028</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26028</link>
      <description>&lt;p&gt;CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted tags. The sanitizer validates only the src attribute of &amp;lt;iframe&amp;gt;, &amp;lt;video&amp;gt;, and &amp;lt;audio&amp;gt; elements, leaving all other attributes unchecked. As a result, an attacker can inject arbitrary HTML through srcdoc, completely defeating CryptPad&amp;#39;s intended bounce sandboxing and enabling link injection or other interactive content within user-controlled documents. The root cause lies in how the sanitizer classifies and enforces tag restrictions: although it defines both forbidden and restricted tag lists, &amp;lt;iframe&amp;gt; is treated as &amp;#34;restricted&amp;#34; rather than &amp;#34;forbidden.&amp;#34; Enforcement then inspects only the src attribute, so pairing a benign blob: src with a malicious srcdoc results in unrestricted rendering. This issue has been fixed in version 2026.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted tags. The sanitizer validates only the src attribute of &amp;lt;iframe&amp;gt;, &amp;lt;video&amp;gt;, and &amp;lt;audio&amp;gt; elements, leaving all other attributes unchecked. As a result, an attacker can inject arbitrary HTML through srcdoc, completely defeating CryptPad&amp;#39;s intended bounce sandboxing and enabling link injection or other interactive content within user-controlled documents. The root cause lies in how the sanitizer classifies and enforces tag restrictions: although it defines both forbidden and restricted tag lists, &amp;lt;iframe&amp;gt; is treated as &amp;#34;restricted&amp;#34; rather than &amp;#34;forbidden.&amp;#34; Enforcement then inspects only the src attribute, so pairing a benign blob: src with a malicious srcdoc results in unrestricted rendering. This issue has been fixed in version 2026.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26028</guid>
    </item>
    <item>
      <title>GHSA-g2g4-47gv-p72v — CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g2g4-47gv-p72v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: cryptpad&lt;/p&gt;
&lt;p&gt;### Summary
CryptPad’s HTML sanitizer in Diffmarked.js can be bypassed due to incomplete filtering of restricted tags.
Because the sanitizer only validates the src attribute of `&amp;lt;iframe&amp;gt;` `&amp;lt;video&amp;gt;`, and `&amp;lt;audio&amp;gt;` elements,  and does not restrict other attributes, an attacker can inject arbitrary HTML through srcdoc. This completely defeats CryptPad’s intended bounce sandboxing and allows link injection or other interactive content inside user-controlled documents.&lt;/p&gt;
&lt;p&gt;### Details
The sanitizer defines forbidden and restricted tags but treats &amp;lt;iframe&amp;gt; as “restricted” instead of “forbidden”:&lt;/p&gt;
&lt;p&gt;https://github.com/cryptpad/cryptpad/blob/0dd3c1f53d56dffb06651b86ead6b9b387920173/www/common/diffMarked.js#L403-L407
The actual enforcement only checks the src attribute, nothing else:&lt;/p&gt;
&lt;p&gt;https://github.com/cryptpad/cryptpad/blob/0dd3c1f53d56dffb06651b86ead6b9b387920173/www/common/diffMarked.js#L445-L449&lt;/p&gt;
&lt;p&gt;Because only src is validated, adding a benign blob: src but malicious srcdoc results in unrestricted rendering.
### PoC&lt;/p&gt;
&lt;p&gt;An attacker can embed arbitrary HTML, including clickable external links, images, or interactive content, completely bypassing CryptPad’s bounce mechanism and sanitization:&lt;/p&gt;
&lt;p&gt;```html
&amp;lt;iframe src=blob: srcdoc=&amp;#34;&amp;lt;a href=https://attacker.com target=_blank&amp;gt;CLICK ME&amp;lt;/a&amp;gt;&amp;#34;&amp;gt;&amp;lt;/iframe&amp;gt;
```&lt;/p&gt;
&lt;p&gt;Although CSP is strict, CryptPad exposes several same-origin gadgets that can execute attacker-controlled code.&lt;/p&gt;
&lt;p&gt;For example, `jscolor.js` dynamically evaluates user-provided options:
https://gith…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: cryptpad&lt;/p&gt;
&lt;p&gt;### Summary
CryptPad’s HTML sanitizer in Diffmarked.js can be bypassed due to incomplete filtering of restricted tags.
Because the sanitizer only validates the src attribute of `&amp;lt;iframe&amp;gt;` `&amp;lt;video&amp;gt;`, and `&amp;lt;audio&amp;gt;` elements,  and does not restrict other attributes, an attacker can inject arbitrary HTML through srcdoc. This completely defeats CryptPad’s intended bounce sandboxing and allows link injection or other interactive content inside user-controlled documents.&lt;/p&gt;
&lt;p&gt;### Details
The sanitizer defines forbidden and restricted tags but treats &amp;lt;iframe&amp;gt; as “restricted” instead of “forbidden”:&lt;/p&gt;
&lt;p&gt;https://github.com/cryptpad/cryptpad/blob/0dd3c1f53d56dffb06651b86ead6b9b387920173/www/common/diffMarked.js#L403-L407
The actual enforcement only checks the src attribute, nothing else:&lt;/p&gt;
&lt;p&gt;https://github.com/cryptpad/cryptpad/blob/0dd3c1f53d56dffb06651b86ead6b9b387920173/www/common/diffMarked.js#L445-L449&lt;/p&gt;
&lt;p&gt;Because only src is validated, adding a benign blob: src but malicious srcdoc results in unrestricted rendering.
### PoC&lt;/p&gt;
&lt;p&gt;An attacker can embed arbitrary HTML, including clickable external links, images, or interactive content, completely bypassing CryptPad’s bounce mechanism and sanitization:&lt;/p&gt;
&lt;p&gt;```html
&amp;lt;iframe src=blob: srcdoc=&amp;#34;&amp;lt;a href=https://attacker.com target=_blank&amp;gt;CLICK ME&amp;lt;/a&amp;gt;&amp;#34;&amp;gt;&amp;lt;/iframe&amp;gt;
```&lt;/p&gt;
&lt;p&gt;Although CSP is strict, CryptPad exposes several same-origin gadgets that can execute attacker-controlled code.&lt;/p&gt;
&lt;p&gt;For example, `jscolor.js` dynamically evaluates user-provided options:
https://gith…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g2g4-47gv-p72v</guid>
    </item>
  </channel>
</rss>
