Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
876118
AlmaLinux
5721
Alpaquita
14074
Alpine
4566
Android
3399
Azure Linux
15771
BellSoft Hardened Containers
717
Bitnami
9093
Chainguard
10582
CleanStart
4482
CRAN
14
crates.io
2698
Debian
65193
Echo
8554
GHC
3
GIT
102763
GitHub Actions
55
Go
8972
Hackage
32
Hex
315
Julia
1713
Linux
28049
Mageia
6148
Maven
6956
MinimOS
136227
npm
228018
NuGet
1845
opam
26
openEuler
8374
openSUSE
14121
OSS-Fuzz
3987
Packagist
6967
Pub
11
PyPI
24767
Red Hat
22653
Rocky Linux
4086
Root
19190
RubyGems
4711
SUSE
22589
SwiftURL
59
TuxCare
8804
Ubuntu
62180
VSCode
20
Wolfi
7613
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7q9c-hpx7-9cwm
npm/@typespec/spector
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
yesterday
Fix available
Severity - 7.5 (High)
GHSA-gx45-xrj5-g6c4
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
yesterday
Fix available
Severity - 8.5 (High)
GHSA-wrj3-vj8c-784f
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
yesterday
Fix available
Severity - 8.5 (High)
GHSA-c6mw-8xh8-gpq6
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
yesterday
Fix available
Severity - 8.3 (High)
GHSA-6v2g-fpxh-pmmh
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning
yesterday
Fix available
Severity - 9.2 (Critical)
GHSA-h539-c7r8-3xq4
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
yesterday
Fix available
Severity - 8.7 (High)
GHSA-7j5w-7r7x-9v27
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
yesterday
Fix available
Severity - 8.5 (High)
GHSA-g29h-pfmp-qp9r
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
yesterday
Fix available
Severity - 7.3 (High)
GHSA-62f5-cp2p-vq95
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
yesterday
Fix available
Severity - 8.7 (High)
GHSA-w7wx-5q49-r59w
crates.io/codewhale-tui
crates.io/deepseek-tui
npm/codewhale
npm/deepseek-tui
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
yesterday
Fix available
Severity - 8.7 (High)
GHSA-6hxq-p678-4hr2
npm/@simplewebauthn/server
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
yesterday
Fix available
Severity - 2.0 (Low)
MAL-2026-15925
npm/tailwind-contact-forms
Malicious code in tailwind-contact-forms (npm)
yesterday
No fix available
MAL-2026-15921
npm/box-sign-client-poc
Malicious code in box-sign-client-poc (npm)
yesterday
No fix available
MAL-2026-15920
npm/box-sign-client
Malicious code in box-sign-client (npm)
yesterday
No fix available
MAL-2026-15922
npm/claude-channel-discord
Malicious code in claude-channel-discord (npm)
yesterday
No fix available
MAL-2026-15924
npm/real-router-telemetry
Malicious code in real-router-telemetry (npm)
yesterday
No fix available
Load more...
npm - OSV