<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:32:53 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-349681</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349681</link>
      <description>EUVD-2026-349681</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349681</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71291</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71291</link>
      <description>&lt;p&gt;Bolt CMS renders content field values through Twig&amp;#39;s full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue calls shouldBeRenderedAsTwig, which gates rendering only on the field definition&amp;#39;s allow_twig flag and a regex checking for , , or ; when true, the raw field value is compiled and rendered via with no sandboxing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Bolt CMS renders content field values through Twig&amp;#39;s full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue calls shouldBeRenderedAsTwig, which gates rendering only on the field definition&amp;#39;s allow_twig flag and a regex checking for , , or ; when true, the raw field value is compiled and rendered via with no sandboxing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71291</guid>
    </item>
    <item>
      <title>GHSA-m6xj-xx3f-5vv9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m6xj-xx3f-5vv9</link>
      <description>&lt;p&gt;Bolt CMS renders content field values through Twig&amp;#39;s full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue() calls shouldBeRenderedAsTwig(), which gates rendering only on the field definition&amp;#39;s allow_twig flag and a regex checking for `{{`, `{%`, or `{#`; when true, the raw field value is compiled and rendered via `self::getTwig()-&amp;gt;createTemplate($value)-&amp;gt;render([&amp;#39;record&amp;#39; =&amp;gt; $this-&amp;gt;getContent()])` with no sandboxing. Bolt&amp;#39;s own bundled config/bolt/contenttypes.yaml sets `allow_twig: true` on the default &amp;#34;pages&amp;#34; contenttype&amp;#39;s content field out of the box. Any user with edit access to that content type (a standard editor role, not just an administrator) can inject a Twig payload such as `{{ [&amp;#39;id&amp;#39;]|map(&amp;#39;passthru&amp;#39;)|join }}` that executes arbitrary OS commands when the content is saved and rendered, achieving remote code execution as the web server user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Bolt CMS renders content field values through Twig&amp;#39;s full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue() calls shouldBeRenderedAsTwig(), which gates rendering only on the field definition&amp;#39;s allow_twig flag and a regex checking for `{{`, `{%`, or `{#`; when true, the raw field value is compiled and rendered via `self::getTwig()-&amp;gt;createTemplate($value)-&amp;gt;render([&amp;#39;record&amp;#39; =&amp;gt; $this-&amp;gt;getContent()])` with no sandboxing. Bolt&amp;#39;s own bundled config/bolt/contenttypes.yaml sets `allow_twig: true` on the default &amp;#34;pages&amp;#34; contenttype&amp;#39;s content field out of the box. Any user with edit access to that content type (a standard editor role, not just an administrator) can inject a Twig payload such as `{{ [&amp;#39;id&amp;#39;]|map(&amp;#39;passthru&amp;#39;)|join }}` that executes arbitrary OS commands when the content is saved and rendered, achieving remote code execution as the web server user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m6xj-xx3f-5vv9</guid>
    </item>
  </channel>
</rss>
