Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
Vulnerability Description
Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by fast-xml-parser. Both fields are validated only as z.string(), placing no restriction on XML special characters. An attacker who controls these values can inject arbitrary XML into the generated RSS feed: a value containing " can break out of an attribute (as with enclosure.type), and a value containing </source> can close an element early and inject additional nodes (as with source.title). This corrupts feed structure, injects false metadata (for example, a fake <link> pointing to a malicious URL), and can cause feed readers to misparse or display attacker-controlled content. In SSR mode (output: 'server'), the poisoned feed is served on every request to all subscribers. This issue has been fixed in version 4.0.19.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Vulnerability Type
XML注入(XPath盲注)
Vulnerability Title
withastro astro 输入验证错误漏洞
Vulnerability Description
withastro astro是withastro的框架。 withastro astro 1.0.0版本至4.0.18版本存在输入验证错误漏洞,该漏洞源于source.title和enclosure.type字段在XML模板中直接插值,未进行XML字符转义,可能导致攻击者注入任意XML,破坏feed结构并注入虚假元数据。
CVSS Information
N/A
Vulnerability Type
N/A