<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 07:14:30 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-342032</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342032</link>
      <description>EUVD-2026-342032</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342032</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59728</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59728</link>
      <description>&lt;p&gt;Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by fast-xml-parser. Both fields are validated only as z.string(), placing no restriction on XML special characters. An attacker who controls these values can inject arbitrary XML into the generated RSS feed: a value containing &amp;#34; can break out of an attribute (as with enclosure.type), and a value containing &amp;lt;/source&amp;gt; can close an element early and inject additional nodes (as with source.title). This corrupts feed structure, injects false metadata (for example, a fake &amp;lt;link&amp;gt; pointing to a malicious URL), and can cause feed readers to misparse or display attacker-controlled content. In SSR mode (output: &amp;#39;server&amp;#39;), the poisoned feed is served on every request to all subscribers. This issue has been fixed in version 4.0.19.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by fast-xml-parser. Both fields are validated only as z.string(), placing no restriction on XML special characters. An attacker who controls these values can inject arbitrary XML into the generated RSS feed: a value containing &amp;#34; can break out of an attribute (as with enclosure.type), and a value containing &amp;lt;/source&amp;gt; can close an element early and inject additional nodes (as with source.title). This corrupts feed structure, injects false metadata (for example, a fake &amp;lt;link&amp;gt; pointing to a malicious URL), and can cause feed readers to misparse or display attacker-controlled content. In SSR mode (output: &amp;#39;server&amp;#39;), the poisoned feed is served on every request to all subscribers. This issue has been fixed in version 4.0.19.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59728</guid>
    </item>
    <item>
      <title>GHSA-8j5q-mfj2-5q9q — @astrojs/rss: XML Injection via Unescaped RSS Feed Fields</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8j5q-mfj2-5q9q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @astrojs/rss&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In `@astrojs/rss`, the `source.title` and `enclosure.type` item fields are interpolated directly into XML template strings without XML-character escaping before being parsed by `fast-xml-parser`. An attacker who controls these field values can inject arbitrary XML elements into the generated RSS feed.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Two fields in `packages/astro-rss/src/index.ts` are affected:&lt;/p&gt;
&lt;p&gt;### `source.title`&lt;/p&gt;
&lt;p&gt;```typescript
item.source = parser.parse(
  `&amp;lt;source url=&amp;#34;${result.source.url}&amp;#34;&amp;gt;${result.source.title}&amp;lt;/source&amp;gt;`,
).source;
```&lt;/p&gt;
&lt;p&gt;`source.title` is validated only as `z.string()`, with no restriction on XML special characters. A value containing `&amp;lt;/source&amp;gt;` followed by arbitrary XML is parsed as real XML elements, merging injected nodes into the RSS item.&lt;/p&gt;
&lt;p&gt;### `enclosure.type`&lt;/p&gt;
&lt;p&gt;```typescript
item.enclosure = parser.parse(
  `&amp;lt;enclosure url=&amp;#34;${enclosureURL}&amp;#34; length=&amp;#34;${result.enclosure.length}&amp;#34; type=&amp;#34;${result.enclosure.type}&amp;#34;/&amp;gt;`,
).enclosure;
```&lt;/p&gt;
&lt;p&gt;`enclosure.type` is also `z.string()` and is interpolated into an XML attribute without escaping. A value containing `&amp;#34;` followed by additional XML can break out of the attribute and inject extra elements.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;`source.title` injection:&lt;/p&gt;
&lt;p&gt;```javascript
source: {
  url: &amp;#39;https://legit.example.com&amp;#39;,
  title: &amp;#39;&amp;lt;/source&amp;gt;&amp;lt;item&amp;gt;&amp;lt;title&amp;gt;INJECTED&amp;lt;/title&amp;gt;&amp;lt;link&amp;gt;https://evil.com&amp;lt;/link&amp;gt;&amp;lt;/item&amp;gt;&amp;lt;source&amp;gt;&amp;#39;,
}
// Result: RSS feed contains an injected &amp;lt;item&amp;gt; element with an evil.com link
```&lt;/p&gt;
&lt;p&gt;`enclosure.type` injection:&lt;/p&gt;
&lt;p&gt;```javascript…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @astrojs/rss&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In `@astrojs/rss`, the `source.title` and `enclosure.type` item fields are interpolated directly into XML template strings without XML-character escaping before being parsed by `fast-xml-parser`. An attacker who controls these field values can inject arbitrary XML elements into the generated RSS feed.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Two fields in `packages/astro-rss/src/index.ts` are affected:&lt;/p&gt;
&lt;p&gt;### `source.title`&lt;/p&gt;
&lt;p&gt;```typescript
item.source = parser.parse(
  `&amp;lt;source url=&amp;#34;${result.source.url}&amp;#34;&amp;gt;${result.source.title}&amp;lt;/source&amp;gt;`,
).source;
```&lt;/p&gt;
&lt;p&gt;`source.title` is validated only as `z.string()`, with no restriction on XML special characters. A value containing `&amp;lt;/source&amp;gt;` followed by arbitrary XML is parsed as real XML elements, merging injected nodes into the RSS item.&lt;/p&gt;
&lt;p&gt;### `enclosure.type`&lt;/p&gt;
&lt;p&gt;```typescript
item.enclosure = parser.parse(
  `&amp;lt;enclosure url=&amp;#34;${enclosureURL}&amp;#34; length=&amp;#34;${result.enclosure.length}&amp;#34; type=&amp;#34;${result.enclosure.type}&amp;#34;/&amp;gt;`,
).enclosure;
```&lt;/p&gt;
&lt;p&gt;`enclosure.type` is also `z.string()` and is interpolated into an XML attribute without escaping. A value containing `&amp;#34;` followed by additional XML can break out of the attribute and inject extra elements.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;`source.title` injection:&lt;/p&gt;
&lt;p&gt;```javascript
source: {
  url: &amp;#39;https://legit.example.com&amp;#39;,
  title: &amp;#39;&amp;lt;/source&amp;gt;&amp;lt;item&amp;gt;&amp;lt;title&amp;gt;INJECTED&amp;lt;/title&amp;gt;&amp;lt;link&amp;gt;https://evil.com&amp;lt;/link&amp;gt;&amp;lt;/item&amp;gt;&amp;lt;source&amp;gt;&amp;#39;,
}
// Result: RSS feed contains an injected &amp;lt;item&amp;gt; element with an evil.com link
```&lt;/p&gt;
&lt;p&gt;`enclosure.type` injection:&lt;/p&gt;
&lt;p&gt;```javascript…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8j5q-mfj2-5q9q</guid>
    </item>
  </channel>
</rss>
