cross-site scripting in nuxt (CVE-2026-56317). Risk of unauthorized operations or information disclosure. Exploitable via ``innerHTML``. Mitigation: upgrade to `3.21.7` or later.
authentication bypass in @capgo/capacitor-native-biometric (CVE-2026-56294). Confidential information can be exposed externally. Exploitable via ``CryptoObject``. Mitigation: upgrade to `8.3.6` or later.
vulnerability in flowise (CVE-2026-56276). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v1/user`. Mitigation: upgrade to `3.1.2` or later.
vulnerability in flowise (CVE-2026-56267). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/account/forgot-password`. Mitigation: upgrade to `3.0.13` or later.