<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 12:34:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-373275</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-373275</link>
      <description>EUVD-2026-373275</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-373275</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63459</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63459</link>
      <description>&lt;p&gt;Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrator-controlled description to a live element&amp;#39;s innerHTML and then reading textContent. Active resource markup can execute an event handler during the innerHTML assignment before textContent is read. A lower-privilege administrator can store such markup in descriptions rendered by the Products list, Collections list, Promotions list, Payment Methods list, or Shipping Methods list, and script executes when another administrator views the affected row. This stored cross-site scripting can compromise the viewing administrator&amp;#39;s session and enable cross-privilege or cross-channel administrative actions. This issue is fixed in version 3.6.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrator-controlled description to a live element&amp;#39;s innerHTML and then reading textContent. Active resource markup can execute an event handler during the innerHTML assignment before textContent is read. A lower-privilege administrator can store such markup in descriptions rendered by the Products list, Collections list, Promotions list, Payment Methods list, or Shipping Methods list, and script executes when another administrator views the affected row. This stored cross-site scripting can compromise the viewing administrator&amp;#39;s session and enable cross-privilege or cross-channel administrative actions. This issue is fixed in version 3.6.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63459</guid>
    </item>
    <item>
      <title>GHSA-xhq9-whgq-49j5 — Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xhq9-whgq-49j5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @vendure/dashboard&lt;/p&gt;
&lt;p&gt;# Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions&lt;/p&gt;
&lt;p&gt;**Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) ·&lt;/p&gt;
&lt;p&gt;## Summary
The dashboard&amp;#39;s `RichTextDescriptionCell` &amp;#34;strips HTML&amp;#34; from an entity&amp;#39;s `description` by assigning it to a live element&amp;#39;s `innerHTML` and reading back `textContent`. This pattern still **executes** active markup: a `description` containing `&amp;lt;img src=x onerror=…&amp;gt;` runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing `onerror`). Because `description` is an admin-settable field shown in multiple list views, a lower-privilege administrator can store a payload that executes in a **higher-privilege administrator&amp;#39;s** browser when they open the corresponding list — stored XSS leading to admin-session compromise.&lt;/p&gt;
&lt;p&gt;## Vulnerable code
`packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx`
```tsx
export const RichTextDescriptionCell: DataTableCellComponent&amp;lt;{ description: string }&amp;gt; = ({ cell }) =&amp;gt; {
    const value = cell.getValue();
    const textContent = useMemo(() =&amp;gt; {
        if (!value) return &amp;#39;&amp;#39;;
        const div = document.createElement(&amp;#39;div&amp;#39;);
        div.innerHTML = value;          // line 51 — parses/loads active markup; &amp;lt;img onerror&amp;gt; fires here
        return div.textContent ?? &amp;#39;&amp;#39;;   // line 52 — reading textContent does NOT undo the side effect
    }, [value]);
    ...
}
```
`innerHTML` does n…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @vendure/dashboard&lt;/p&gt;
&lt;p&gt;# Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions&lt;/p&gt;
&lt;p&gt;**Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) ·&lt;/p&gt;
&lt;p&gt;## Summary
The dashboard&amp;#39;s `RichTextDescriptionCell` &amp;#34;strips HTML&amp;#34; from an entity&amp;#39;s `description` by assigning it to a live element&amp;#39;s `innerHTML` and reading back `textContent`. This pattern still **executes** active markup: a `description` containing `&amp;lt;img src=x onerror=…&amp;gt;` runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing `onerror`). Because `description` is an admin-settable field shown in multiple list views, a lower-privilege administrator can store a payload that executes in a **higher-privilege administrator&amp;#39;s** browser when they open the corresponding list — stored XSS leading to admin-session compromise.&lt;/p&gt;
&lt;p&gt;## Vulnerable code
`packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx`
```tsx
export const RichTextDescriptionCell: DataTableCellComponent&amp;lt;{ description: string }&amp;gt; = ({ cell }) =&amp;gt; {
    const value = cell.getValue();
    const textContent = useMemo(() =&amp;gt; {
        if (!value) return &amp;#39;&amp;#39;;
        const div = document.createElement(&amp;#39;div&amp;#39;);
        div.innerHTML = value;          // line 51 — parses/loads active markup; &amp;lt;img onerror&amp;gt; fires here
        return div.textContent ?? &amp;#39;&amp;#39;;   // line 52 — reading textContent does NOT undo the side effect
    }, [value]);
    ...
}
```
`innerHTML` does n…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xhq9-whgq-49j5</guid>
    </item>
  </channel>
</rss>
