CVE-2026-59728P4MEDIUM≥ 1.0.0, < 4.0.192026-07-20
CVE-2026-59728 [MEDIUM] CWE-91 @astrojs/rss: XML Injection via Unescaped RSS Feed Fields
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
## Summary
In `@astrojs/rss`, the `source.title` and `enclosure.type` item fields are interpolated directly into XML template strings without XML-character escaping before being parsed by `fast-xml-parser`. An attacker who controls these field values can inject arbitrary XML elements into the generated RSS feed.
## Details
Two fields in `packages/
ghsa