Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
RUSTSEC-2026-0283
  • crates.io/clear_on_drop
clear_on_drop is unmaintained 22 hours ago
  • No fix available
GHSA-m3wp-48jr-vr4g
  • crates.io/mistralrs-server-core
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS 3 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-wfgq-w7cq-qj7j
  • crates.io/mistralrs-server-core
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url 3 days ago
  • Fix available
  • Severity - 7.2 (High)
GHSA-7rhf-42qf-vrvc
  • crates.io/gix-sec
gix-sec safe.directory protections absent for elevated administrators 4 days ago
  • Fix available
  • Severity - 6.8 (Medium)
RUSTSEC-2026-0282
  • crates.io/aligned_box
Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics 4 days ago
  • Fix available
GHSA-5qr2-v392-m9g8
  • crates.io/swc_html_minifier
  • npm/@swc/html
SWC HTML minifier may allow script element breakout when minifying embedded JSON 5 days ago
  • Fix available
  • Severity - 6.1 (Medium)
RUSTSEC-2026-0280
  • crates.io/greentic-setup-dev
`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code 6 days ago
  • Fix available
RUSTSEC-2026-0281
  • crates.io/greentic-setup
`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code 6 days ago
  • Fix available
GHSA-66r2-5gwj-gxm2
  • crates.io/surrealdb-core
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions 04 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-848m-r628-vrxw
  • crates.io/surrealdb
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path 04 Sep
  • Fix available
  • Severity - 8.1 (High)
GHSA-gx45-xrj5-g6c4
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository 04 Sep
  • Fix available
  • Severity - 8.5 (High)
GHSA-wrj3-vj8c-784f
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE) 04 Sep
  • Fix available
  • Severity - 8.5 (High)
GHSA-c6mw-8xh8-gpq6
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval 04 Sep
  • Fix available
  • Severity - 8.3 (High)
GHSA-6v2g-fpxh-pmmh
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning 04 Sep
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-h539-c7r8-3xq4
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: js_execution leaks parent environment to model context via missing env scrub 04 Sep
  • Fix available
  • Severity - 8.7 (High)
GHSA-7j5w-7r7x-9v27
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval 04 Sep
  • Fix available
  • Severity - 8.5 (High)