<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Tailwind CSS</title>
  <link>https://cvedaily.com/pages/tags/tailwind-css.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/tailwind-css.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Tailwind CSS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-44429 – The MCP Registry provides MCP clients with a list of MCP servers, like an app st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44429</guid>
    <pubDate>Thu, 14 May 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44429</strong></p>
  <p>The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served at GET / (file internal/api/handlers/v0/ui_index.html) is vulnerable to stored cross-site scripting via the server.websiteUrl field of any published server.json. Server-side validation in internal/validators/validators.go (validateWebsiteURL) only che…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44301 – Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44301</guid>
    <pubDate>Tue, 12 May 2026 22:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44301</strong></p>
  <p>Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configured Node tools without restrictions on file system access. As a result, executing hugo against an untrusted site could allow code running through these tools to read or write files outside the project's working director…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53104 – gluestack-ui is a library of copy-pasteable components &amp; patterns crafted with T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53104</guid>
    <pubDate>Tue, 01 Jul 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53104</strong></p>
  <p>gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commit e6b4271, a command injection vulnerability was discovered in the discussion-to-slack.yml GitHub Actions workflow. Untrusted discussion fields (title, body, etc.) were directly interpolated into shell commands in a run: block. An attacker could craft a malicious GitHub Discussi…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53104">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
