<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 21:54:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-370606</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-370606</link>
      <description>EUVD-2026-370606</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-370606</guid>
    </item>
    <item>
      <title>fkie_cve-2026-92795</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92795</link>
      <description>&lt;p&gt;Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata endpoints and internal services reachable only from the backend network, reading responses containing sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata endpoints and internal services reachable only from the backend network, reading responses containing sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-92795</guid>
    </item>
    <item>
      <title>GHSA-mc6j-cg9w-v46r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mc6j-cg9w-v46r</link>
      <description>&lt;p&gt;Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata endpoints and internal services reachable only from the backend network, reading responses containing sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata endpoints and internal services reachable only from the backend network, reading responses containing sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mc6j-cg9w-v46r</guid>
    </item>
  </channel>
</rss>
