<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 12:24:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-372134</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-372134</link>
      <description>EUVD-2026-372134</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-372134</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63671</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63671</link>
      <description>&lt;p&gt;MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and unsafeLinkPrefix to remove executable URLs from untrusted Markdown. validateProp checks only attributes named href or src, allowing an SVG xlink:href value represented as xLinkHref to retain a javascript: URL that executes in the page origin when selected. The data:text/html denylist entries are also compared against url.protocol, which is only data:, so an iframe src containing data:text/html survives sanitization and executes in an opaque origin when loaded. Plain href javascript: URLs, srcdoc, object, script, and base elements are already blocked, making these two paths specific sibling gaps in the sanitizer. This issue is fixed in version 0.22.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and unsafeLinkPrefix to remove executable URLs from untrusted Markdown. validateProp checks only attributes named href or src, allowing an SVG xlink:href value represented as xLinkHref to retain a javascript: URL that executes in the page origin when selected. The data:text/html denylist entries are also compared against url.protocol, which is only data:, so an iframe src containing data:text/html survives sanitization and executes in an opaque origin when loaded. Plain href javascript: URLs, srcdoc, object, script, and base elements are already blocked, making these two paths specific sibling gaps in the sanitizer. This issue is fixed in version 0.22.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63671</guid>
    </item>
    <item>
      <title>GHSA-mxm6-v9r6-r94c — @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the defau…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mxm6-v9r6-r94c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @nuxtjs/mdc&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`@nuxtjs/mdc` renders untrusted markdown (including raw HTML) to a Vue component tree. Across two prior advisories it added a URL/attribute sanitizer to block dangerous links in that HTML: `validateProps` / `validateProp` and an `unsafeLinkPrefix` deny-list (`dist/runtime/parser/utils/props.js`). The sanitizer runs at parse time (`dist/runtime/parser/compiler.js`) and `parseMarkdown` enables raw HTML by default (`allowDangerousHtml: true`, `dist/runtime/parser/options.js`), so the sanitizer is the only barrier and it applies with no configuration required.&lt;/p&gt;
&lt;p&gt;Two sibling vectors bypass that sanitizer at the default configuration:&lt;/p&gt;
&lt;p&gt;1. SVG anchor `xlink:href`. `validateProp` only scheme-checks attributes named exactly `href` or `src`:&lt;/p&gt;
&lt;p&gt;```
   if (attribute === &amp;#34;href&amp;#34; || attribute === &amp;#34;src&amp;#34;) return isAnchorLinkAllowed(value);
   return true;
   ```&lt;/p&gt;
&lt;p&gt;An `xlink:href` (parsed to the hast property `xLinkHref`) is neither, so a `javascript:` URL on an SVG `&amp;lt;a&amp;gt;` is passed through. The renderer maps the property back to the real attribute (`MDCRenderer.vue`: `find(html, &amp;#34;xLinkHref&amp;#34;).attribute` is `xlink:href`), so the output element is `&amp;lt;a xlink:href=&amp;#34;javascript:...&amp;#34;&amp;gt;`. Clicking it runs the script in the page origin. Plain `&amp;lt;a href=&amp;#34;javascript:...&amp;#34;&amp;gt;` is correctly stripped, which is what makes this the un-patched sibling.&lt;/p&gt;
&lt;p&gt;2. `&amp;lt;iframe src=&amp;#34;data:text/html,...&amp;#34;&amp;gt;`. `data:text/html` is present in `unsafeLinkPrefix`, but the check compares it against `url.protocol`:&lt;/p&gt;
&lt;p&gt;```…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @nuxtjs/mdc&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`@nuxtjs/mdc` renders untrusted markdown (including raw HTML) to a Vue component tree. Across two prior advisories it added a URL/attribute sanitizer to block dangerous links in that HTML: `validateProps` / `validateProp` and an `unsafeLinkPrefix` deny-list (`dist/runtime/parser/utils/props.js`). The sanitizer runs at parse time (`dist/runtime/parser/compiler.js`) and `parseMarkdown` enables raw HTML by default (`allowDangerousHtml: true`, `dist/runtime/parser/options.js`), so the sanitizer is the only barrier and it applies with no configuration required.&lt;/p&gt;
&lt;p&gt;Two sibling vectors bypass that sanitizer at the default configuration:&lt;/p&gt;
&lt;p&gt;1. SVG anchor `xlink:href`. `validateProp` only scheme-checks attributes named exactly `href` or `src`:&lt;/p&gt;
&lt;p&gt;```
   if (attribute === &amp;#34;href&amp;#34; || attribute === &amp;#34;src&amp;#34;) return isAnchorLinkAllowed(value);
   return true;
   ```&lt;/p&gt;
&lt;p&gt;An `xlink:href` (parsed to the hast property `xLinkHref`) is neither, so a `javascript:` URL on an SVG `&amp;lt;a&amp;gt;` is passed through. The renderer maps the property back to the real attribute (`MDCRenderer.vue`: `find(html, &amp;#34;xLinkHref&amp;#34;).attribute` is `xlink:href`), so the output element is `&amp;lt;a xlink:href=&amp;#34;javascript:...&amp;#34;&amp;gt;`. Clicking it runs the script in the page origin. Plain `&amp;lt;a href=&amp;#34;javascript:...&amp;#34;&amp;gt;` is correctly stripped, which is what makes this the un-patched sibling.&lt;/p&gt;
&lt;p&gt;2. `&amp;lt;iframe src=&amp;#34;data:text/html,...&amp;#34;&amp;gt;`. `data:text/html` is present in `unsafeLinkPrefix`, but the check compares it against `url.protocol`:&lt;/p&gt;
&lt;p&gt;```…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mxm6-v9r6-r94c</guid>
    </item>
  </channel>
</rss>
