VulnScope — package-centric CVE lookup- MEDIUM4.4CVE-2026-55650Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure
- CRITICAL9.6Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
- HIGH7.5Langflow: Unauthenticated DoS through multipart form boundary file upload
- MEDIUM6.1Langflow: Logout button does not clear session
- CRITICAL9.9Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
- —py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
- —py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
- MEDIUM6.1Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering
- MEDIUM6.2Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read
- MEDIUM6.8dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
- —TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
- HIGH7.8@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
- HIGH7.5flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
- —@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument
- MEDIUM6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
- —Python Liquid: Infinite loop when parsing malformed `{% case %}` tags
- —parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
- HIGH7.1jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
- —jupyterlab-git extension: Stored XSS leading to RCE
- HIGH7.5Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- HIGH7.6Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
- HIGH8.0py7zr: Arbitrary File Write Vulnerability
- HIGH7.3Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
- HIGH8.8CedarJava has policy injection vulnerability
- HIGH8.8CedarJava has type confusion vulnerability