-
CVE-2025-13465: Defect that allows prototype manipulation through crafted object paths.
-
CVE-2025-64756: Defect that allows crafted filenames to trigger command injection and arbitrary command execution.
-
CVE-2025-64718: Defect that allows prototype pollution when parsing malicious YAML input.
-
CVE-2025-68470: Defect that allows crafted navigation paths to trigger unintended redirects to external URLs.
-
CVE-2026-21884: Defect that allows cross-site scripting through improperly sanitized input during server-side rendering.
-
CVE-2026-22029: Defect that could allow improper input handling, leading to potential denial of service.
-
CVE-2026-22030: Defect that could allow improper input handling, leading to potential denial of service.
-
CVE-2026-25639: Defect that could allow improper input validation, leading to denial of service.
-
CVE-2026-27606: Defect that allows path traversal to overwrite files on the host filesystem.
-
CVE-2026-27903: Defect that allows crafted glob patterns to cause excessive processing and denial of service.
-
CVE-2026-29063: Defect that allows prototype pollution through crafted input, potentially altering object behavior.
-
CVE‑2023‑28154: Defect that allows mishandled import parsing to enable cross‑realm object access and potential code compromise.
-
CVE‑2024‑43788: Defect that could allow cross‑site scripting via improper input validation.
-
CVE-2025-15284: Defect that allows attackers to bypass array limits and exhaust server resources via crafted requests.
-
CVE‑2025‑30359: Defect that could allow source code exposure when serving content from a development server.
-
CVE‑2025‑30360: Defect that could allow source code exfiltration via inadequate WebSocket origin validation.
-
CVE-2025-68157: Defect that could allow specially crafted input to cause denial of service.
-
CVE-2025-68458: Defect that could allow improper handling of input leading to unintended behavior or denial of service.
-
CVE-2026-2391: Defect that could allow memory corruption, leading to potential code execution.
-
CVE-2026-22029: Defect that could allow improper input handling, leading to potential denial of service.