VulnScope — package-centric CVE lookup- CRITICAL9.8CVE-2026-0755gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
- LOW2.2Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
- LOW2.5Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
- CRITICAL10.0n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
- CRITICAL9.9n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
- CRITICAL9.6n8n: Credential Exfiltration via Permission Bypass
- CRITICAL9.0LobeHub: Unauthenticated SSRF in `/webapi/proxy`
- CRITICAL9.9n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
- LOW3.1React Router: Potential CSRF via PUT/PATCH/DELETE document requests
- CRITICAL9.8Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
- LOW3.2@babel/core: Arbitrary File Read via sourceMappingURL Comment
- CRITICAL9.0Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
- LOW3.5Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
- CRITICAL10.0DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
- CRITICAL9.6Vitest browser mode serves unsanitized otelCarrier query parameter as inline script
- CRITICAL9.8When Vitest UI server is listening, arbitrary file can be read and executed
- CRITICAL10.0NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
- CRITICAL9.8vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
- CRITICAL10.0vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
- CRITICAL10.0vm2 is Vulnerable to Sandbox Breakout Through Promise Species
- CRITICAL10.0vm2 has a Sandbox Escape issue
- LOW3.7Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
- CRITICAL10.0LiquidJS is Vulnerable to Remote Code Execution
- CRITICAL9.6OCI layer symlink escape → arbitrary host write
- CRITICAL10.0Read-only volume remount bypass via guest CAP_SYS_ADMIN