Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-59728
Published:July 21, 2026
Updated:July 21, 2026
Summary In "@astrojs/rss", the "source.title" and "enclosure.type" item fields are interpolated directly into XML template strings without XML-character escaping before being parsed by "fast-xml-parser". An attacker who controls these field values can inject arbitrary XML elements into the generated RSS feed. Details Two fields in "packages/astro-rss/src/index.ts" are affected: "source.title" item.source = parser.parse( "<source url="${result.source.url}">${result.source.title}</source>", ).source; "source.title" is validated only as "z.string()", with no restriction on XML special characters. A value containing "</source>" followed by arbitrary XML is parsed as real XML elements, merging injected nodes into the RSS item. "enclosure.type" item.enclosure = parser.parse( "<enclosure url="${enclosureURL}" length="${result.enclosure.length}" type="${result.enclosure.type}"/>", ).enclosure; "enclosure.type" is also "z.string()" and is interpolated into an XML attribute without escaping. A value containing """ followed by additional XML can break out of the attribute and inject extra elements. Proof of Concept "source.title" injection: source: { url: 'https://legit.example.com', title: '</source><item><title>INJECTED</title><link>https://evil.com</link></item><source>', } // Result: RSS feed contains an injected <item> element with an evil.com link "enclosure.type" injection: enclosure: { url: 'https://example.com/a.mp3', length: 0, type: 'audio/mpeg" /><link>https://evil.example.com</link><enclosure fake="', } // Result: RSS feed contains an injected <link> element Both injections were confirmed with "fast-xml-parser": the injected ""link": "https://evil.com"" appears in the parsed output. Impact An attacker who can control "source.title" or "enclosure.type" values (e.g., via a CMS, database, or user-submitted content that populates "RSSFeedItem") can inject arbitrary XML into the generated RSS feed. This corrupts feed structure, injects false metadata (e.g., a fake "<link>" pointing to a malicious URL), and can cause feed readers to misparse or display attacker-controlled content. In SSR mode ("output: 'server'"), the poisoned feed is served on every request to all subscribers. Patches Fixed in "@astrojs/rss@4.0.19".
Affected Packages
https://github.com/withastro/astro.git (GITHUB):
Affected version(s) >=@astrojs/rss@1.0.0 <@astrojs/rss@4.0.19
Fix Suggestion:
Update to version @astrojs/rss@4.0.19
@astrojs/rss (NPM):
Affected version(s) >=1.0.0 <4.0.19
Fix Suggestion:
Update to version 4.0.19
Do you need more information?
Contact Us
CVSS v4
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
4.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE
Weakness Type (CWE)
XML Injection (aka Blind XPath Injection)