<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 16:19:30 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322911</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322911</link>
      <description>EUVD-2026-322911</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322911</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45627</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45627</link>
      <description>&lt;p&gt;Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via strings.ReplaceAll with no escaping. The substitution lands inside a &amp;lt;style&amp;gt; element of the embedded logo.svg, allowing an attacker to close the style block and inject executable &amp;lt;script&amp;gt; content. Because the response is served as image/svg+xml and Arcane sets no Content-Security-Policy or X-Content-Type-Options headers, navigating a logged-in admin victim to a crafted URL executes attacker-controlled JavaScript in Arcane&amp;#39;s origin and rides the victim&amp;#39;s HttpOnly JWT cookie to fully compromise the admin account. This vulnerability is fixed in 1.19.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via strings.ReplaceAll with no escaping. The substitution lands inside a &amp;lt;style&amp;gt; element of the embedded logo.svg, allowing an attacker to close the style block and inject executable &amp;lt;script&amp;gt; content. Because the response is served as image/svg+xml and Arcane sets no Content-Security-Policy or X-Content-Type-Options headers, navigating a logged-in admin victim to a crafted URL executes attacker-controlled JavaScript in Arcane&amp;#39;s origin and rides the victim&amp;#39;s HttpOnly JWT cookie to fully compromise the admin account. This vulnerability is fixed in 1.19.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45627</guid>
    </item>
    <item>
      <title>GHSA-q2pj-8v84-9mh5 — Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q2pj-8v84-9mh5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/getarcaneapp/arcane/backend&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The unauthenticated `GET /api/app-images/logo` endpoint reflects a user-supplied `color` query parameter into the body of an SVG document via `strings.ReplaceAll` with no escaping. The substitution lands inside a `&amp;lt;style&amp;gt;` element of the embedded `logo.svg`, allowing an attacker to close the style block and inject executable `&amp;lt;script&amp;gt;` content. Because the response is served as `image/svg+xml` and Arcane sets no Content-Security-Policy or `X-Content-Type-Options` headers, navigating a logged-in admin victim to a crafted URL executes attacker-controlled JavaScript in Arcane&amp;#39;s origin and rides the victim&amp;#39;s HttpOnly JWT cookie to fully compromise the admin account.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The route is registered in `backend/internal/huma/handlers/appimages.go:53-61` with an explicitly empty security requirement, marking it as public:&lt;/p&gt;
&lt;p&gt;```go
huma.Register(api, huma.Operation{
    OperationID: &amp;#34;get-logo&amp;#34;,
    Method:      http.MethodGet,
    Path:        &amp;#34;/app-images/logo&amp;#34;,
    ...
    Security:    []map[string][]string{}, // explicit: no auth
}, h.GetLogo)
```&lt;/p&gt;
&lt;p&gt;`backend/internal/huma/middleware/auth.go:209-213` honors the empty `Security` value by returning `reqs.isRequired == false` and short-circuiting with `next(ctx)`, so no JWT/API-key check runs.&lt;/p&gt;
&lt;p&gt;`GetLogoInput.Color` (`appimages.go:23`) is declared with no validation tags:&lt;/p&gt;
&lt;p&gt;```go
type GetLogoInput struct {
    Full  bool   `query:&amp;#34;full&amp;#34; default:&amp;#34;false&amp;#34; ...`
    Color string `query:&amp;#34;color&amp;#34; doc:&amp;#34;Optional accent color overri…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/getarcaneapp/arcane/backend&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The unauthenticated `GET /api/app-images/logo` endpoint reflects a user-supplied `color` query parameter into the body of an SVG document via `strings.ReplaceAll` with no escaping. The substitution lands inside a `&amp;lt;style&amp;gt;` element of the embedded `logo.svg`, allowing an attacker to close the style block and inject executable `&amp;lt;script&amp;gt;` content. Because the response is served as `image/svg+xml` and Arcane sets no Content-Security-Policy or `X-Content-Type-Options` headers, navigating a logged-in admin victim to a crafted URL executes attacker-controlled JavaScript in Arcane&amp;#39;s origin and rides the victim&amp;#39;s HttpOnly JWT cookie to fully compromise the admin account.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The route is registered in `backend/internal/huma/handlers/appimages.go:53-61` with an explicitly empty security requirement, marking it as public:&lt;/p&gt;
&lt;p&gt;```go
huma.Register(api, huma.Operation{
    OperationID: &amp;#34;get-logo&amp;#34;,
    Method:      http.MethodGet,
    Path:        &amp;#34;/app-images/logo&amp;#34;,
    ...
    Security:    []map[string][]string{}, // explicit: no auth
}, h.GetLogo)
```&lt;/p&gt;
&lt;p&gt;`backend/internal/huma/middleware/auth.go:209-213` honors the empty `Security` value by returning `reqs.isRequired == false` and short-circuiting with `next(ctx)`, so no JWT/API-key check runs.&lt;/p&gt;
&lt;p&gt;`GetLogoInput.Color` (`appimages.go:23`) is declared with no validation tags:&lt;/p&gt;
&lt;p&gt;```go
type GetLogoInput struct {
    Full  bool   `query:&amp;#34;full&amp;#34; default:&amp;#34;false&amp;#34; ...`
    Color string `query:&amp;#34;color&amp;#34; doc:&amp;#34;Optional accent color overri…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q2pj-8v84-9mh5</guid>
    </item>
  </channel>
</rss>
