<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 14:34:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275188</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275188</link>
      <description>EUVD-2026-275188</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275188</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30913</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30913</link>
      <description>&lt;p&gt;Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is inserted verbatim into plain-text notification emails, and recipients may be misled into visiting attacker-controlled domains.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is inserted verbatim into plain-text notification emails, and recipients may be misled into visiting attacker-controlled domains.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30913</guid>
    </item>
    <item>
      <title>GHSA-3c4m-j3g4-hh25 — flarum/nicknames extension has display name injection in notification emails (autolink &amp; markdown)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3c4m-j3g4-hh25</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: flarum/nicknames&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When the `flarum/nicknames` extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is inserted verbatim into plain-text notification emails, and recipients may be misled into visiting attacker-controlled domains.&lt;/p&gt;
&lt;p&gt;## Affected package&lt;/p&gt;
&lt;p&gt;- **`flarum/nicknames`** — permissive display name driver that allows special characters; affected since initial release on the `1.x` branch&lt;/p&gt;
&lt;p&gt;Any third-party display name driver that permits special characters would be equally affected.&lt;/p&gt;
&lt;p&gt;## Variants&lt;/p&gt;
&lt;p&gt;1. **Domain autolink** — a nickname such as `nasty.com` is automatically converted to a clickable hyperlink by virtually all email clients (Gmail, Outlook, Apple Mail, Thunderbird).
2. **Markdown link syntax** — a nickname such as `[CLICK](https://evil.com)` is rendered as a clickable hyperlink by email clients that auto-render markdown in plain-text emails (e.g. Apple Mail, Thunderbird).&lt;/p&gt;
&lt;p&gt;## Steps to reproduce&lt;/p&gt;
&lt;p&gt;**Variant 1 (autolink — affects all email clients)**
1. Enable `flarum/nicknames`, set nickname to `nasty.com`
2. Trigger a notification email to another user (e.g. follow them, mention them)
3. The nickname appears as a clickable link in the received email&lt;/p&gt;
&lt;p&gt;**Variant 2 (markdown — affects markdown-rendering email clients)**
1. Enable `flarum/nicknames`, set nickname to `[CLICK](https://evil.com)`
2. Trigger a notification email to another user
3. In a markdown-rendering email client (e.g. Apple Mail),…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: flarum/nicknames&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When the `flarum/nicknames` extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is inserted verbatim into plain-text notification emails, and recipients may be misled into visiting attacker-controlled domains.&lt;/p&gt;
&lt;p&gt;## Affected package&lt;/p&gt;
&lt;p&gt;- **`flarum/nicknames`** — permissive display name driver that allows special characters; affected since initial release on the `1.x` branch&lt;/p&gt;
&lt;p&gt;Any third-party display name driver that permits special characters would be equally affected.&lt;/p&gt;
&lt;p&gt;## Variants&lt;/p&gt;
&lt;p&gt;1. **Domain autolink** — a nickname such as `nasty.com` is automatically converted to a clickable hyperlink by virtually all email clients (Gmail, Outlook, Apple Mail, Thunderbird).
2. **Markdown link syntax** — a nickname such as `[CLICK](https://evil.com)` is rendered as a clickable hyperlink by email clients that auto-render markdown in plain-text emails (e.g. Apple Mail, Thunderbird).&lt;/p&gt;
&lt;p&gt;## Steps to reproduce&lt;/p&gt;
&lt;p&gt;**Variant 1 (autolink — affects all email clients)**
1. Enable `flarum/nicknames`, set nickname to `nasty.com`
2. Trigger a notification email to another user (e.g. follow them, mention them)
3. The nickname appears as a clickable link in the received email&lt;/p&gt;
&lt;p&gt;**Variant 2 (markdown — affects markdown-rendering email clients)**
1. Enable `flarum/nicknames`, set nickname to `[CLICK](https://evil.com)`
2. Trigger a notification email to another user
3. In a markdown-rendering email client (e.g. Apple Mail),…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3c4m-j3g4-hh25</guid>
    </item>
  </channel>
</rss>
