Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
874803
AlmaLinux
5714
Alpaquita
14074
Alpine
4566
Android
3399
Azure Linux
15575
BellSoft Hardened Containers
717
Bitnami
9093
Chainguard
10569
CleanStart
4482
CRAN
14
crates.io
2698
Debian
65167
Echo
8525
GHC
3
GIT
102720
GitHub Actions
55
Go
8972
Hackage
32
Hex
314
Julia
1713
Linux
28049
Mageia
6148
Maven
6956
MinimOS
135361
npm
228018
NuGet
1845
opam
26
openEuler
8257
openSUSE
14121
OSS-Fuzz
3985
Packagist
6967
Pub
11
PyPI
24766
Red Hat
22653
Rocky Linux
4084
Root
19190
RubyGems
4711
SUSE
22589
SwiftURL
59
TuxCare
8804
Ubuntu
62180
VSCode
20
Wolfi
7601
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7q9c-hpx7-9cwm
npm/@typespec/spector
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
13 hours ago
Fix available
Severity - 7.5 (High)
GHSA-gx45-xrj5-g6c4
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
17 hours ago
Fix available
Severity - 8.5 (High)
GHSA-wrj3-vj8c-784f
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
17 hours ago
Fix available
Severity - 8.5 (High)
GHSA-c6mw-8xh8-gpq6
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
17 hours ago
Fix available
Severity - 8.3 (High)
GHSA-6v2g-fpxh-pmmh
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning
17 hours ago
Fix available
Severity - 9.2 (Critical)
GHSA-h539-c7r8-3xq4
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
17 hours ago
Fix available
Severity - 8.7 (High)
GHSA-7j5w-7r7x-9v27
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
17 hours ago
Fix available
Severity - 8.5 (High)
GHSA-g29h-pfmp-qp9r
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
17 hours ago
Fix available
Severity - 7.3 (High)
GHSA-62f5-cp2p-vq95
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
17 hours ago
Fix available
Severity - 8.7 (High)
GHSA-w7wx-5q49-r59w
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
17 hours ago
Fix available
Severity - 8.7 (High)
GHSA-6hxq-p678-4hr2
npm/@simplewebauthn/server
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
17 hours ago
Fix available
Severity - 2.0 (Low)
MAL-2026-15925
npm/tailwind-contact-forms
Malicious code in tailwind-contact-forms (npm)
yesterday
No fix available
MAL-2026-15921
npm/box-sign-client-poc
Malicious code in box-sign-client-poc (npm)
yesterday
No fix available
MAL-2026-15920
npm/box-sign-client
Malicious code in box-sign-client (npm)
yesterday
No fix available
MAL-2026-15922
npm/claude-channel-discord
Malicious code in claude-channel-discord (npm)
yesterday
No fix available
MAL-2026-15924
npm/real-router-telemetry
Malicious code in real-router-telemetry (npm)
yesterday
No fix available
Load more...
npm - OSV