<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 17:44:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-323410</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323410</link>
      <description>EUVD-2026-323410</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323410</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44651</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44651</link>
      <description>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, when fetch(url) throws, the code sends:
res.status(500).send(&amp;#39;Error occurred while trying to proxy to: &amp;#39; + url + &amp;#39; &amp;#39; + error). The url value is attacker-controlled (req.params.url) and is not HTML-escaped before rendering. This vulnerability is fixed in 1.18.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, when fetch(url) throws, the code sends:
res.status(500).send(&amp;#39;Error occurred while trying to proxy to: &amp;#39; + url + &amp;#39; &amp;#39; + error). The url value is attacker-controlled (req.params.url) and is not HTML-escaped before rendering. This vulnerability is fixed in 1.18.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44651</guid>
    </item>
    <item>
      <title>GHSA-xc4x-2452-5gc9 — SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xc4x-2452-5gc9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;## Resolution&lt;/p&gt;
&lt;p&gt;Fixed in SillyTavern 1.18.0: a user-provided URL is no longer reflected in the HTTP response body.&lt;/p&gt;
&lt;p&gt;## Overview
- Vulnerability Type: XSS
- Affected Location: `src/middleware/corsProxy.js:40`
- Trigger Scenario: reflected XSS in CORS proxy error response&lt;/p&gt;
&lt;p&gt;## Root Cause
When `fetch(url)` throws, the code sends:
`res.status(500).send(&amp;#39;Error occurred while trying to proxy to: &amp;#39; + url + &amp;#39; &amp;#39; + error)`.
The `url` value is attacker-controlled (`req.params.url`) and is not HTML-escaped before rendering.&lt;/p&gt;
&lt;p&gt;## Source-to-Sink Chain
1. Source (user-controlled input)
- Entry point: `GET /proxy/:url(*)`&lt;/p&gt;
&lt;p&gt;2. Data flow
- Code analysis shows concrete propagation into this sink:
  - vulnerability title: `Reflected XSS in CORS proxy error response`
  - sink location reached by attacker-controlled input: `src/middleware/corsProxy.js:40`
- The same sink behavior is confirmed by controlled execution observations.&lt;/p&gt;
&lt;p&gt;3. Sink (dangerous operation)
- Sink location: `src/middleware/corsProxy.js:40`
- Vulnerable behavior: reflected XSS in CORS proxy error response&lt;/p&gt;
&lt;p&gt;## Exploitation Preconditions
1. The attacker can inject controllable content into a rendered response.
2. The vulnerable rendering context does not apply strict output encoding/sanitization.
3. A victim user opens the affected page or response.&lt;/p&gt;
&lt;p&gt;## Risk
This issue enables script execution in the victim context and can compromise session or data integrity.&lt;/p&gt;
&lt;p&gt;## Impact
An attacker may run arbitrary JavaScript in the victim context…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;## Resolution&lt;/p&gt;
&lt;p&gt;Fixed in SillyTavern 1.18.0: a user-provided URL is no longer reflected in the HTTP response body.&lt;/p&gt;
&lt;p&gt;## Overview
- Vulnerability Type: XSS
- Affected Location: `src/middleware/corsProxy.js:40`
- Trigger Scenario: reflected XSS in CORS proxy error response&lt;/p&gt;
&lt;p&gt;## Root Cause
When `fetch(url)` throws, the code sends:
`res.status(500).send(&amp;#39;Error occurred while trying to proxy to: &amp;#39; + url + &amp;#39; &amp;#39; + error)`.
The `url` value is attacker-controlled (`req.params.url`) and is not HTML-escaped before rendering.&lt;/p&gt;
&lt;p&gt;## Source-to-Sink Chain
1. Source (user-controlled input)
- Entry point: `GET /proxy/:url(*)`&lt;/p&gt;
&lt;p&gt;2. Data flow
- Code analysis shows concrete propagation into this sink:
  - vulnerability title: `Reflected XSS in CORS proxy error response`
  - sink location reached by attacker-controlled input: `src/middleware/corsProxy.js:40`
- The same sink behavior is confirmed by controlled execution observations.&lt;/p&gt;
&lt;p&gt;3. Sink (dangerous operation)
- Sink location: `src/middleware/corsProxy.js:40`
- Vulnerable behavior: reflected XSS in CORS proxy error response&lt;/p&gt;
&lt;p&gt;## Exploitation Preconditions
1. The attacker can inject controllable content into a rendered response.
2. The vulnerable rendering context does not apply strict output encoding/sanitization.
3. A victim user opens the affected page or response.&lt;/p&gt;
&lt;p&gt;## Risk
This issue enables script execution in the victim context and can compromise session or data integrity.&lt;/p&gt;
&lt;p&gt;## Impact
An attacker may run arbitrary JavaScript in the victim context…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xc4x-2452-5gc9</guid>
    </item>
  </channel>
</rss>
