Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7q9c-hpx7-9cwm
  • npm/@typespec/spector
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop 13 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-gx45-xrj5-g6c4
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository 17 hours ago
  • Fix available
  • Severity - 8.5 (High)
GHSA-wrj3-vj8c-784f
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE) 17 hours ago
  • Fix available
  • Severity - 8.5 (High)
GHSA-c6mw-8xh8-gpq6
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval 17 hours ago
  • Fix available
  • Severity - 8.3 (High)
GHSA-6v2g-fpxh-pmmh
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning 17 hours ago
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-h539-c7r8-3xq4
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: js_execution leaks parent environment to model context via missing env scrub 17 hours ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-7j5w-7r7x-9v27
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval 17 hours ago
  • Fix available
  • Severity - 8.5 (High)
GHSA-g29h-pfmp-qp9r
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation) 17 hours ago
  • Fix available
  • Severity - 7.3 (High)
GHSA-62f5-cp2p-vq95
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository 17 hours ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-w7wx-5q49-r59w
  • crates.io/codewhale-tui
  • crates.io/deepseek-tui
  • npm/codewhale
  • npm/deepseek-tui
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes 17 hours ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-6hxq-p678-4hr2
  • npm/@simplewebauthn/server
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor 17 hours ago
  • Fix available
  • Severity - 2.0 (Low)
MAL-2026-15925
  • npm/tailwind-contact-forms
Malicious code in tailwind-contact-forms (npm) yesterday
  • No fix available
MAL-2026-15921
  • npm/box-sign-client-poc
Malicious code in box-sign-client-poc (npm) yesterday
  • No fix available
MAL-2026-15920
  • npm/box-sign-client
Malicious code in box-sign-client (npm) yesterday
  • No fix available
MAL-2026-15922
  • npm/claude-channel-discord
Malicious code in claude-channel-discord (npm) yesterday
  • No fix available
MAL-2026-15924
  • npm/real-router-telemetry
Malicious code in real-router-telemetry (npm) yesterday
  • No fix available