Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73222 |
|
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
|
| CVE-2026-58043 |
|
Vulnerability in nodejs (CVE-2026-58043)
vulnerability in nodejs (CVE-2026-58043). Confidential information can be exposed externally.
|
| CVE-2026-56847 |
|
Vulnerability in nodejs (CVE-2026-56847)
vulnerability in nodejs (CVE-2026-56847). Confidential information can be exposed externally.
|
| CVE-2026-56850 |
|
Authentication Bypass in nodejs (CVE-2026-56850)
authentication bypass in nodejs (CVE-2026-56850). Data can be tampered with by attackers.
|
| CVE-2026-15157 |
|
Vulnerability in undici (CVE-2026-15157)
vulnerability in undici (CVE-2026-15157). Risk of unauthorized operations or information disclosure. Exploitable via ``body.type``. Mitigation: upgrade to `6.24.0` or later.
|
| CVE-2026-14643 |
|
Vulnerability in undici (CVE-2026-14643)
vulnerability in undici (CVE-2026-14643). Confidential information can be exposed externally. Exploitable via ``private``. Mitigation: upgrade to `8.9.0` or later.
|
| CVE-2026-16728 |
|
Vulnerability in undici (CVE-2026-16728)
vulnerability in undici (CVE-2026-16728). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.9.0` or later.
|
| CVE-2026-16729 |
|
Vulnerability in undici (CVE-2026-16729)
vulnerability in undici (CVE-2026-16729). Risk of unauthorized operations or information disclosure. Exploitable via ``setCookie``. Mitigation: upgrade to `8.9.0` or later.
|
| CVE-2026-13697 |
|
Information Disclosure in undici (CVE-2026-13697)
vulnerability in undici (CVE-2026-13697). Confidential information can be exposed externally. Exploitable via ``private``. Mitigation: upgrade to `8.9.0` or later.
|
| CVE-2026-15074 |
|
@fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to route guard bypass via path traversal
|
| CVE-2026-16158 |
|
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destinat...
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs....
|
| CVE-2026-15631 |
|
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
|
| CVE-2026-48934 |
|
Vulnerability in node (CVE-2026-48934)
vulnerability in node (CVE-2026-48934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48935 |
|
Vulnerability in node (CVE-2026-48935)
vulnerability in node (CVE-2026-48935). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48936 |
|
Vulnerability in node (CVE-2026-48936)
vulnerability in node (CVE-2026-48936). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.3.1` or later.
|
| CVE-2026-48619 |
|
Vulnerability in node (CVE-2026-48619)
vulnerability in node (CVE-2026-48619). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48933 |
|
Vulnerability in nodejs (CVE-2026-48933)
vulnerability in nodejs (CVE-2026-48933). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48615 |
|
Vulnerability in node (CVE-2026-48615)
vulnerability in node (CVE-2026-48615). Confidential information can be exposed externally. Exploitable via ``ERR_PROXY_TUNNEL``. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48930 |
|
Vulnerability in node (CVE-2026-48930)
vulnerability in node (CVE-2026-48930). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48928 |
|
Vulnerability in node (CVE-2026-48928)
vulnerability in node (CVE-2026-48928). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48618 |
|
Vulnerability in nodejs (CVE-2026-48618)
vulnerability in nodejs (CVE-2026-48618). Confidential information can be exposed externally.
|
| CVE-2026-54639 |
|
Style Dictionary - Prototype Pollution in convertTokenData utility function
Style Dictionary - Prototype Pollution in convertTokenData utility function
|
| CVE-2026-48931 |
|
Vulnerability in node (CVE-2026-48931)
vulnerability in node (CVE-2026-48931). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48937 |
|
Vulnerability in nodejs (CVE-2026-48937)
vulnerability in nodejs (CVE-2026-48937). Risk of unauthorized operations or information disclosure. Exploitable via ``GOAWAY``.
|
| CVE-2026-48617 |
|
Vulnerability in nodejs (CVE-2026-48617)
vulnerability in nodejs (CVE-2026-48617). Confidential information can be exposed externally.
|
| CVE-2026-9697 |
|
Vulnerability in undici (CVE-2026-9697)
vulnerability in undici (CVE-2026-9697). Confidential information can be exposed externally. Exploitable via ``ProxyAgent``. Mitigation: upgrade to `8.5.0` or later.
|
| CVE-2026-9679 |
|
Vulnerability in undici (CVE-2026-9679)
vulnerability in undici (CVE-2026-9679). Data can be tampered with by attackers. Exploitable via ``parseSetCookie``. Mitigation: upgrade to `8.5.0` or later.
|
| CVE-2026-9678 |
|
Vulnerability in undici (CVE-2026-9678)
vulnerability in undici (CVE-2026-9678). Confidential information can be exposed externally. Exploitable via ``private``. Mitigation: upgrade to `8.5.0` or later.
|
| CVE-2026-6733 |
|
Vulnerability in undici (CVE-2026-6733)
vulnerability in undici (CVE-2026-6733). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.5.0` or later.
|
| CVE-2026-6734 |
|
Vulnerability in undici (CVE-2026-6734)
vulnerability in undici (CVE-2026-6734). Successful exploitation can lead to full system takeover. Exploitable via ``Socks5ProxyAgent``. Mitigation: upgrade to `8.2.0` or later.
|
| CVE-2026-11525 |
|
Vulnerability in undici (CVE-2026-11525)
vulnerability in undici (CVE-2026-11525). Risk of unauthorized operations or information disclosure. Exploitable via ``SameSite``. Mitigation: upgrade to `8.5.0` or later.
|
| CVE-2026-9675 |
|
Vulnerability in undici (CVE-2026-9675)
vulnerability in undici (CVE-2026-9675). Risk of unauthorized operations or information disclosure. Exploitable via ``maxPayloadSize``. Mitigation: upgrade to `8.5.0` or later.
|
| CVE-2026-12151 |
|
Vulnerability in undici (CVE-2026-12151)
vulnerability in undici (CVE-2026-12151). Risk of unauthorized operations or information disclosure. Exploitable via ``maxPayloadSize``. Mitigation: upgrade to `8.5.0` or later.
|
| CVE-2026-53864 |
|
OpenClaw: Host environment sanitizer missed two Node.js control variables
OpenClaw: Host environment sanitizer missed two Node.js control variables
|
| CVE-2026-44313 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44313)
SSRF in ssrf (CVE-2026-44313). Confidential information can be exposed externally. Exploitable via `GET /api/v1/archives/{linkId}`.
|
| CVE-2026-41512 |
|
Code Injection in gem (CVE-2026-41512)
code injection in gem (CVE-2026-41512). Successful exploitation can lead to full system takeover. Exploitable via `POST /targets/auto_detect_selectors`.
|
| CVE-2026-43944 |
|
Vulnerability in electerm (CVE-2026-43944)
vulnerability in electerm (CVE-2026-43944). Successful exploitation can lead to full system takeover. Exploitable via ``opts``. Mitigation: upgrade to `> 3.8.8` or later.
|
| CVE-2025-63706 |
|
Code Injection in npm (CVE-2025-63706)
code injection in npm (CVE-2025-63706). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26956 |
|
Vulnerability in vm2-project (CVE-2026-26956)
vulnerability in vm2-project (CVE-2026-26956). Successful exploitation can lead to full system takeover. Exploitable via ``catch``.
|
| CVE-2026-24118 |
|
Code Injection in vm2-project (CVE-2026-24118)
code injection in vm2-project (CVE-2026-24118). Successful exploitation can lead to full system takeover. Exploitable via ``__lookupGetter__``.
|
| CVE-2026-24120 |
|
Code Injection in vm2-project (CVE-2026-24120)
code injection in vm2-project (CVE-2026-24120). Successful exploitation can lead to full system takeover. Exploitable via ``resetPromiseSpecies``.
|
| CVE-2026-24781 |
|
Code Injection in vm2-project (CVE-2026-24781)
code injection in vm2-project (CVE-2026-24781). Successful exploitation can lead to full system takeover. Exploitable via ``inspect``.
|
| CVE-2026-21710 |
|
Vulnerability in node (CVE-2026-21710)
vulnerability in node (CVE-2026-21710). Risk of unauthorized operations or information disclosure. Exploitable via ``TypeError``. Mitigation: upgrade to `20.20.2, 22.22.2, 24.14.1, 25.8.2` or later.
|
| CVE-2026-21717 |
|
Vulnerability in nodejs (CVE-2026-21717)
vulnerability in nodejs (CVE-2026-21717). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21716 |
|
Vulnerability in nodejs (CVE-2026-21716)
vulnerability in nodejs (CVE-2026-21716). Risk of unauthorized operations or information disclosure. Exploitable via ``FileHandle``.
|
| CVE-2026-21715 |
|
Vulnerability in nodejs (CVE-2026-21715)
vulnerability in nodejs (CVE-2026-21715). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21714 |
|
Vulnerability in nodejs (CVE-2026-21714)
vulnerability in nodejs (CVE-2026-21714). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21711 |
|
Vulnerability in nodejs (CVE-2026-21711)
vulnerability in nodejs (CVE-2026-21711). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21713 |
|
Vulnerability in nodejs (CVE-2026-21713)
vulnerability in nodejs (CVE-2026-21713). Confidential information can be exposed externally.
|
| CVE-2026-21712 |
|
Vulnerability in nodejs (CVE-2026-21712)
vulnerability in nodejs (CVE-2026-21712). Risk of unauthorized operations or information disclosure.
|