<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 05:38:00 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343789</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343789</link>
      <description>EUVD-2026-343789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343789</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45376</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45376</link>
      <description>&lt;p&gt;Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions before sanitization, allowing an authenticated organization administrator to execute blind PostgreSQL expressions and infer data through timing differences. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions before sanitization, allowing an authenticated organization administrator to execute blind PostgreSQL expressions and infer data through timing differences. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45376</guid>
    </item>
    <item>
      <title>GHSA-jvqq-cvh4-xm37 — Decidim: Admin user search allows SQL injection through similarity-based sorting</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jvqq-cvh4-xm37</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: decidim-admin&lt;/p&gt;
&lt;p&gt;The admin organization user search uses the untrusted term value inside raw SQL ORDER BY expressions. Because the value is interpolated before Rails sanitization is applied, a crafted search string is executed by PostgreSQL as part of the sort expression.&lt;/p&gt;
&lt;p&gt;### Technical description
 
The vulnerable endpoint is exposed as GET `/admin/organization/users` in `decidim-admin/config/routes.rb`:&lt;/p&gt;
&lt;p&gt;```ruby
resource :organization, only: [:edit, :update], controller: &amp;#34;organization&amp;#34; do
  member do
    get :users
  end
end
```&lt;/p&gt;
&lt;p&gt;That route reaches `Decidim::Admin::OrganizationController#users`, which forwards the current organization&amp;#39;s available users into `search`:&lt;/p&gt;
&lt;p&gt;```ruby
def users
  search(current_organization.users.available)
end
```&lt;/p&gt;
&lt;p&gt;Inside `search`, the attacker-controlled source is `params[:term]`:&lt;/p&gt;
&lt;p&gt;```ruby
if (term = params[:term].to_s).present?
```&lt;/p&gt;
&lt;p&gt;The query has two branches. In both branches, the `WHERE` predicates use bind parameters and are not the injection sink. The vulnerability is in the subsequent `.order(Arel.sql(...))` calls, where the untrusted value is interpolated directly into SQL string literals.&lt;/p&gt;
&lt;p&gt;Nickname branch:&lt;/p&gt;
&lt;p&gt;```ruby
nickname = term.delete(&amp;#34;@&amp;#34;)
relation.where(&amp;#34;nickname LIKE ?&amp;#34;, &amp;#34;#{nickname}%&amp;#34;)
  .order(Arel.sql(ActiveRecord::Base.sanitize_sql_array(&amp;#34;similarity(nickname, &amp;#39;#{nickname}&amp;#39;) DESC&amp;#34;)))
```&lt;/p&gt;
&lt;p&gt;Name/email branch:&lt;/p&gt;
&lt;p&gt;```ruby
relation.where(&amp;#34;name ILIKE ?&amp;#34;, &amp;#34;%#{term}%&amp;#34;).or(
  relation.where(&amp;#34;email ILIKE ?&amp;#34;, &amp;#34;%#{term}%&amp;#34;)
)
  .order(Arel.sql(ActiveRecord::Base…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: decidim-admin&lt;/p&gt;
&lt;p&gt;The admin organization user search uses the untrusted term value inside raw SQL ORDER BY expressions. Because the value is interpolated before Rails sanitization is applied, a crafted search string is executed by PostgreSQL as part of the sort expression.&lt;/p&gt;
&lt;p&gt;### Technical description
 
The vulnerable endpoint is exposed as GET `/admin/organization/users` in `decidim-admin/config/routes.rb`:&lt;/p&gt;
&lt;p&gt;```ruby
resource :organization, only: [:edit, :update], controller: &amp;#34;organization&amp;#34; do
  member do
    get :users
  end
end
```&lt;/p&gt;
&lt;p&gt;That route reaches `Decidim::Admin::OrganizationController#users`, which forwards the current organization&amp;#39;s available users into `search`:&lt;/p&gt;
&lt;p&gt;```ruby
def users
  search(current_organization.users.available)
end
```&lt;/p&gt;
&lt;p&gt;Inside `search`, the attacker-controlled source is `params[:term]`:&lt;/p&gt;
&lt;p&gt;```ruby
if (term = params[:term].to_s).present?
```&lt;/p&gt;
&lt;p&gt;The query has two branches. In both branches, the `WHERE` predicates use bind parameters and are not the injection sink. The vulnerability is in the subsequent `.order(Arel.sql(...))` calls, where the untrusted value is interpolated directly into SQL string literals.&lt;/p&gt;
&lt;p&gt;Nickname branch:&lt;/p&gt;
&lt;p&gt;```ruby
nickname = term.delete(&amp;#34;@&amp;#34;)
relation.where(&amp;#34;nickname LIKE ?&amp;#34;, &amp;#34;#{nickname}%&amp;#34;)
  .order(Arel.sql(ActiveRecord::Base.sanitize_sql_array(&amp;#34;similarity(nickname, &amp;#39;#{nickname}&amp;#39;) DESC&amp;#34;)))
```&lt;/p&gt;
&lt;p&gt;Name/email branch:&lt;/p&gt;
&lt;p&gt;```ruby
relation.where(&amp;#34;name ILIKE ?&amp;#34;, &amp;#34;%#{term}%&amp;#34;).or(
  relation.where(&amp;#34;email ILIKE ?&amp;#34;, &amp;#34;%#{term}%&amp;#34;)
)
  .order(Arel.sql(ActiveRecord::Base…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jvqq-cvh4-xm37</guid>
    </item>
  </channel>
</rss>
