// vulnerability research
Vulnerability research for AI-built websites and apps.
Source-grounded notes on vulnerabilities that matter to AI-generated web apps, BaaS stacks, frontend bundles, auth, and dependency security.
Redis RESTORE Memory-Safety Vulnerability (CVE-2026-25243)
CVE-2026-25243 is a high-severity Redis memory-safety flaw in RESTORE processing. It requires authenticated access and permission to run RESTORE, and Redis 8.6.3 includes the security fix.
All research
126 articles
Active Storage Arbitrary File Read with Potential RCE (CVE-2026-66066)
CVE-2026-66066 is an Active Storage arbitrary file-read vulnerability with potential follow-on RCE in affected Rails branches. FixVibe GitHub repository scans flag affected activestorage versions in Gemfile.lock.
HubSpot Jinjava JavaType Sandbox Bypass (CVE-2025-59340)
CVE-2025-59340 affects HubSpot Jinjava versions >=2.7.0 and <2.7.5, and version 2.8.0. A JavaType deserialization sandbox bypass may enable arbitrary file reads or SSRF and, in some deployments, follow-on RCE; RCE is not guaranteed. FixVibe repository scans flag affected Jinjava versions.
Jenkins config.xml Deserialization Vulnerability (CVE-2026-53435)
CVE-2026-53435 affects Jenkins core releases through weekly 2.567 and LTS 2.555.2 when attacker-controlled configuration is processed under the required permissions. FixVibe repository scans flag affected Jenkins core versions in Maven or Gradle builds.
mcp-server-kubernetes npm Argument Injection Can Expose Cluster Credentials
CVE-2026-61459 is a Critical argument-injection vulnerability in the Node.js npm package mcp-server-kubernetes before 3.9.0. FixVibe covers it with a High-severity, version-based repository advisory that deliberately excludes the unrelated same-named PyPI distribution.
jsPDF Node.js Path Traversal and Local File Inclusion (CVE-2025-68428)
The Node.js bundles of npm package jspdf version 3.0.4 and earlier can read local files when attacker-influenced paths reach loadFile, addImage, html, or addFont. Browser builds are not affected, and jsPDF 4.0.0 restricts filesystem access by default. FixVibe GitHub repo scans flag affected jspdf versions.
Microsoft Kiota Generation-Time SSRF and File Inclusion (CVE-2026-59867)
Microsoft Kiota releases before 1.29.1 and releases from 1.30.0 through 1.32.4 can follow unrestricted external OpenAPI references during client generation. If a developer or CI job processes an attacker-influenced description, the build host may make internal network requests or read local files. FixVibe GitHub repo scans flag affected Kiota versions.
Stored XSS in osTicket Installation Script (CVE-2019-14750)
osTicket releases before 1.10.7 and 1.12.x before 1.12.1 contain a stored cross-site scripting flaw in the installer workflow. FixVibe GitHub repo scans flag the affected installer source.
9router Missing Authorization and OS Command Injection (CVE-2026-59800)
Reviewed advisories identify missing authorization and operating-system command injection in 9router releases before 0.4.44. FixVibe GitHub repo scans flag affected 9router versions in npm manifests and lockfiles.
runc Container Breakout via File Descriptor Leak (CVE-2024-21626)
CVE-2024-21626 is a high-severity runc file-descriptor leak that can let malicious images or container processes reach the host filesystem. FixVibe repo scans flag container working-directory configuration associated with the breakout condition.
Authentication Bypass in MLflow Job Endpoints (CVE-2026-0545)
CVE-2026-0545 is an MLflow authentication-boundary flaw affecting FastAPI job routes when Basic Auth and job execution are enabled. FixVibe verified active scans flag job routes that do not enforce the configured authentication.
NocoBase Sandbox Escape and Remote Code Execution (CVE-2026-34156)
NocoBase @nocobase/plugin-workflow-javascript versions through 2.0.27 are affected by CVE-2026-34156. An authenticated user who can run a Workflow Script Node may escape its sandbox and execute code on the host. FixVibe repo scans flag affected plugin versions.
Microsoft Kiota Command Injection via Malicious OpenAPI Metadata (CVE-2026-59865)
Microsoft Kiota releases before 1.32.5 could trust dependency-install guidance supplied by an OpenAPI description. Exploitation requires an untrusted or compromised description and a developer or integration that follows the supplied install action. Kiota 1.32.5 removes support for description-supplied dependency install commands, and FixVibe now reports affected repository-managed Kiota versions as a version-based advisory.
CVE-2025-56005: Disputed Unsafe Deserialization Risk in PLY
PLY parser construction can opt into loading parser tables through Python pickle. That becomes a code-execution risk only when a less-trusted actor can influence the existing pickle file or its path. CVE-2025-56005 is disputed; FixVibe repo scans flag explicit use of the unsafe parser-table loading path as a likely issue.
Remote Code Execution in verot/class.upload.php (CVE-2019-19576)
CVE-2019-19576 affects dangerous-file handling in verot/class.upload.php releases before 1.0.3 and from 2.0.0 through 2.0.3. FixVibe GitHub repo scans flag affected versions in Composer files.
LobeHub Unauthenticated SSRF in /webapi/proxy (CVE-2026-54157)
LobeHub versions through 2.1.56 expose an unauthenticated server-side proxy route. FixVibe verified active scans flag deployments where that route fetches external URLs for unauthenticated callers.
Next.js WebSocket SSRF Vulnerability (CVE-2026-44578)
CVE-2026-44578 is a high-severity server-side request forgery vulnerability affecting self-hosted applications that use the built-in Next.js server. Vercel-hosted deployments are not affected. FixVibe authorized GitHub repository scans flag affected Next.js versions.
Conditional NGINX HTTP/2 and gRPC Proxy Buffer Overflow (CVE-2026-42055)
CVE-2026-42055 is a conditional heap-based buffer overflow in NGINX HTTP/2 and gRPC upstream proxying. F5 scores it 8.1 High under CVSS v3.1, while nginx.org classifies it Medium. Exploitation requires several uncommon configuration prerequisites, including oversized client-header buffers; worker restart is the direct documented impact, and code execution additionally requires ASLR to be disabled or bypassed. FixVibe repo scans flag affected official NGINX Open Source container deployments with that configuration.
vLLM video-processing RCE advisory (CVE-2026-22778)
CVE-2026-22778 affects vLLM releases from 0.8.3 through 0.14.0 when a deployment serves a video-capable model and processes attacker-controlled video input. vLLM 0.14.1 fixes the issue. FixVibe GitHub repo scans flag affected vLLM versions.
ChromaDB Python Backend Pre-Authentication RCE (CVE-2026-45829)
CVE-2026-45829 affects ChromaDB's optional Python FastAPI backend when attacker-controlled embedding configuration is processed before authorization. The default Rust frontend is not affected.
Gitea Insufficient Permission Checks for Composer Package Source Links (CVE-2026-27771)
Gitea versions through 1.26.1 can expose Composer package source-link information when package and linked-repository permissions differ. FixVibe GitHub repo scans flag pinned Gitea server images in the affected range.
Denial of Service in Newtonsoft.Json via StackOverflow Exception (CVE-2024-21907)
Newtonsoft.Json versions affected by CVE-2024-21907 (GHSA-5crp-9r3c-p9vr) can crash with a stack overflow on deeply nested JSON. GitHub repo scans flag NuGet project and lockfile entries that resolve an affected version.
Command Injection in curlrequest (CVE-2020-7646)
`curlrequest` through 1.0.1 is associated with CVE-2020-7646 / GHSA-m8xj-5v73-3hh8, an OS command injection. FixVibe GitHub repo scans flag affected curlrequest versions in npm manifests and lockfiles.
Authenticated Command Injection in Nginx-UI (CVE-2024-22198)
Nginx-UI releases before the fixed Go pseudo-version 1.9.10-0.20231219184941-827e76c46e63, and application beta releases before 2.0.0.beta.9, are affected by an authenticated command-injection flaw. FixVibe GitHub repo scans flag affected Nginx-UI Go module versions.
OS Command Injection in op-browser (CVE-2020-7625)
op-browser is affected by CVE-2020-7625 / GHSA-3hq6-rmv7-39vh, an OS command injection. FixVibe GitHub repo scans flag npm manifests and lockfiles that resolve affected op-browser versions.
Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry
FixVibe GitHub repo scans now flag @injectivelabs/sdk-ts 1.20.21 and associated @injectivelabs 1.20.21 package evidence in manifests and lockfiles as a version-based malware advisory.
Improper Access Control in Apache ActiveMQ Artemis (CVE-2021-26118)
CVE-2021-26118 is an improper access control issue in Apache ActiveMQ Artemis OpenWire handling before 2.16.0. FixVibe GitHub repo scans flag Maven and Gradle build files that resolve affected org.apache.activemq:artemis-openwire-protocol versions.
Command Injection in get-git-data (CVE-2020-7619)
get-git-data through 1.3.1 is listed as affected by OS command injection. FixVibe GitHub repo scans flag affected get-git-data versions in npm manifests and lockfiles.
OS Command Injection in strong-nginx-controller (CVE-2020-7621)
The strong-nginx-controller npm package is affected by CVE-2020-7621 / GHSA-4v9w-pvwr-38h3 through version 1.0.2. FixVibe GitHub repo scans flag affected versions in npm manifests and lockfiles.
NumPy Deserialization of Untrusted Data (CVE-2019-6446)
Numpy versions prior to 1.16.3 allow for the deserialization of untrusted data through the numpy.load() function when the allow_pickle parameter is set to True. This can lead to arbitrary code execution if an attacker can influence the file being loaded.
OS Command Injection in karma-mojo (CVE-2020-7626)
karma-mojo 1.0.1 and earlier is affected by CVE-2020-7626, an OS command injection. FixVibe GitHub repo scans flag affected karma-mojo versions in npm manifests and lockfiles.
OS Command Injection in install-package (CVE-2020-7629)
install-package 0.4.0 and earlier is affected by CVE-2020-7629, an OS command injection. FixVibe GitHub repo scans flag affected install-package versions in npm manifests and lockfiles.
OS Command Injection in node-key-sender (CVE-2020-7627)
FixVibe GitHub repo scans can now flag npm manifests and lockfiles that resolve node-key-sender versions affected by CVE-2020-7627 / GHSA-4xrw-wvmq-8jmh as version-based advisory evidence.
Milvus Unauthenticated REST API Access on Metrics Port (CVE-2026-26190)
FixVibe verified active scans flag Milvus metrics-port REST API exposure for CVE-2026-26190 / GHSA-7ppg-37fh-vcr6.
OS Command Injection in git-add-remote (CVE-2020-7630)
The git-add-remote npm package is vulnerable to OS command injection. Attackers can execute arbitrary commands on the host system by providing malicious input to the package's functions, which fail to properly sanitize arguments before passing them to the system shell.
OS Command Injection in jscover (CVE-2020-7623)
jscover through 1.0.0 is affected by CVE-2020-7623 command injection. FixVibe GitHub repo scans flag affected jscover versions in npm manifests and lockfiles.
Denial of Service in Go net/url via Unbounded Query Parameters (CVE-2025-61726)
Go fixed CVE-2025-61726 in the standard library net/url query parser. FixVibe GitHub repository scans flag repositories that build with an affected Go release and parse query or form input.
Denial of Service in React Server Components (CVE-2026-23864)
Multiple denial of service (DoS) vulnerabilities exist in React Server Components, specifically affecting the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. Attackers can trigger these vulnerabilities by sending specially crafted HTTP requests to Server Functions, potentially exhausting server resources or crashing the application process.
Unauthenticated SQL Injection in QCubed profile.php (CVE-2020-24913)
CVE-2020-24913 affects QCubed releases before 3.2 through profile.php SQL injection risk. FixVibe GitHub repo scans flag affected qcubed/qcubed versions in Composer files.
QCubed PHP Object Injection in profile.php (CVE-2020-24914)
QCubed releases before 3.2 are affected by a profile.php PHP object-injection advisory. FixVibe GitHub repo scans flag affected qcubed/qcubed versions in Composer files.
Authentication Bypass via SQL Injection in Sourcecodetester Daily Tracker System 1.0 (CVE-2020-24193)
Daily Tracker System 1.0 has a critical CVE-2020-24193 login SQL injection/authentication-bypass issue. FixVibe GitHub repo scans flag the vulnerable login source.
CVE-2020-24036: PHP Object Injection in ForkCMS Backend Ajax Endpoint
A high-severity PHP object-injection advisory affects ForkCMS versions before 5.8.3. FixVibe GitHub repo scans flag affected forkcms/forkcms versions in Composer files.
Arbitrary Code Execution in Handlebars via AST Injection (CVE-2026-33937)
A critical Handlebars advisory affects versions 4.0.0 through 4.7.8 when attacker-controlled AST objects are passed to compile(). FixVibe GitHub repo scans flag affected handlebars versions in npm manifests and lockfiles.
Rancher Command Injection via Unsanitized YAML Parameter (CVE-2026-44939)
CVE-2026-44939 affects Rancher Manager cluster-import manifest generation in affected Rancher release lines. FixVibe now covers it as a GitHub repo version-based advisory when authorized repository evidence shows affected Rancher Manager Go module or deployment image versions. Upgrade Rancher Manager to the fixed release for the branch in use and protect cluster-registration tokens.
Apache Derby LDAP Injection in Authenticator (CVE-2022-46337)
Apache Derby is affected by CVE-2022-46337 / GHSA-rcjc-c4pj-xxrp, an LDAP injection in the authenticator. FixVibe repo scans flag Maven and Gradle projects that resolve affected org.apache.derby:derby versions.
Arbitrary File Write in Rollup via Path Traversal (CVE-2026-27606)
Rollup versions before 2.80.0, 3.30.0, and 4.59.0 are tied to CVE-2026-27606 / GHSA-mw96-cpmx-2vgc. FixVibe repo scans flag affected Rollup versions in npm manifests and lockfiles.
Dolibarr ERP CRM Remote Code Evaluation (CVE-2018-25357)
Dolibarr ERP CRM versions before 6.0.8 and 7.0.0 through 7.0.3 are associated with CVE-2018-25357 / GHSA-hxmh-2xc4-c894. FixVibe passive scans flag public Dolibarr deployments that expose an affected version.
Authorization Bypass in gRPC-Go via HTTP/2 :path Pseudo-Header (CVE-2026-33186)
CVE-2026-33186 affects gRPC-Go servers that combine affected versions with path-based authorization and fallback-allow policy behavior. FixVibe GitHub repo scans flag google.golang.org/grpc versions before 1.79.3.
urllib3 Decompression Bomb Vulnerability (CVE-2026-21441)
urllib3 releases from 1.22 through 2.6.2 can bypass streaming decompression-bomb safeguards when redirect responses are drained. FixVibe reports affected Python dependency evidence and points teams to urllib3 2.6.3 or newer.
Axios Denial of Service via mergeConfig TypeError (CVE-2026-25639)
Axios versions before 0.30.3 and 1.13.5 are affected by a mergeConfig TypeError denial-of-service advisory when untrusted configuration objects with prototype-related keys reach request config. FixVibe GitHub repo scans flag affected axios versions.
TYPO3 Content Element Selector Remote Code Execution (CVE-2026-46725)
TYPO3's third-party Content Element Selector extension (mmc/ceselector) has affected Composer release branches for CVE-2026-46725 / GHSA-8x3j-439w-537c. FixVibe GitHub repo scans flag affected mmc/ceselector versions in Composer files.
AngularJS Regular Expression Denial of Service (CVE-2024-21490)
AngularJS 1.3.0 through 1.8.3 is affected by CVE-2024-21490, a regular-expression denial of service in ng-srcset handling. FixVibe GitHub repo scans flag affected AngularJS dependencies in npm, Bower, Maven and Gradle projects.
Buffer Overflow in Google.Protobuf (CVE-2015-5237)
Google.Protobuf versions before 3.4.0 are associated with CVE-2015-5237 / GHSA-jwvw-v7c5-m82h. FixVibe GitHub repo scans flag affected Google.Protobuf versions in NuGet projects and lockfiles.
HTTP Request Smuggling in Netty (CVE-2019-16869)
Netty releases affected by CVE-2019-16869 / GHSA-p979-4mfw-53vg can create HTTP request-smuggling risk in deployments where Netty parses traffic behind an intermediary. FixVibe GitHub repo scans flag affected Netty Maven and Gradle dependencies.
Gradio Absolute Path Traversal on Windows with Python 3.13+ (CVE-2026-28414)
Gradio versions before 6.7.0 can expose a path traversal risk on Windows with Python 3.13+. FixVibe GitHub repo scans flag affected Gradio dependencies and note when the repository targets that runtime.
Critical Sandbox Breakout in vm2 via Promise Species (CVE-2026-47208)
FixVibe GitHub repo scans can now report npm manifest and lockfile evidence for vm2 versions associated with CVE-2026-47208 / GHSA-76w7-j9cq-rx2j.
Compromised GitHub Action codfish/semantic-release-action Steals CI/CD Secrets
Compromised codfish/semantic-release-action refs can put release workflows and CI/CD secrets at risk. FixVibe GitHub repo scans flag workflow YAML that references the affected refs.
Critical Command Injection in AVideo via Video Link Embedding
AVideo versions before 12.4 are affected by CVE-2023-25313 / GHSA-pgvh-p3g4-86jw. FixVibe now covers this through safe Composer dependency evidence in GitHub repo scans.
Reflected XSS in Label Studio via label_config Parameter
Label Studio versions before 1.18.0 have a reflected XSS issue in the label_config upload-example workflow. FixVibe verified active scans flag affected Label Studio deployments for CVE-2025-47783.
MindsDB Path Traversal in /api/files Leading to Remote Code Execution (CVE-2026-27483)
A critical path traversal vulnerability exists in the MindsDB `/api/files` endpoint. Attackers can exploit this flaw to read or write arbitrary files on the server, ultimately leading to Remote Code Execution (RCE). Users should upgrade to version 25.9.1.1 or later.
Authenticated Command Injection in MISP STIX Import (CVE-2018-19908)
A critical command injection vulnerability was identified in MISP versions 2.4.9x prior to 2.4.99. The flaw exists within the STIX 1 import functionality where unescaped filename strings are used to construct shell commands, allowing authenticated attackers to achieve remote code execution.
Denial of Service Vulnerability in proxy npm Package
The npm proxy package has a denial-of-service advisory for versions >=2.0.0 and <2.1.1. FixVibe GitHub repo scans flag affected proxy versions for CVE-2023-2968 / GHSA-mj6p-3pc9-wf5m.
Apache Airflow Improper Output Encoding (CVE-2024-45498)
Apache Airflow 2.10.0 shipped an example-DAG issue tracked as CVE-2024-45498 / GHSA-c392-whpc-vfpr. FixVibe GitHub repo scans flag the affected apache-airflow dependency.
Arbitrary File Overwrite in ONNX download_model_with_test_data
ONNX before 1.16.2 is affected by CVE-2024-5187 / GHSA-6rq9-53c3-f7vj, an arbitrary file overwrite in download_model_with_test_data. FixVibe repo scans flag affected onnx versions and the calls that use it.
Spring Data Commons XMLBeam XXE (CVE-2018-1259)
Spring Data Commons CVE-2018-1259 is an XXE advisory that depends on affected Spring Data Commons and XMLBeam versions. FixVibe GitHub repo scans flag projects that use both.
Glances REST API Unauthenticated Access (CVE-2026-32596)
Glances can expose REST API telemetry without authentication when its web server is reachable from untrusted networks. FixVibe verified active scans flag Glances REST APIs that return monitoring data without credentials on the scanned origin.
Command Injection and File Overwrite in Perl GD Library (CVE-2026-11526)
Perl GD versions before 2.86 are affected by CVE-2026-11526 when untrusted pathname strings reach filename-accepting GD::Image constructors. FixVibe GitHub repo scans flag affected GD versions in CPAN dependency files.
Nokogiri Affected by libxslt Use-After-Free Vulnerability (CVE-2019-18197)
Nokogiri before 1.10.5 can carry a libxslt use-after-free and uninitialized-data disclosure issue. FixVibe GitHub repo scans flag affected Nokogiri versions in Gemfile, Gemfile.lock, and gemspec files.
SSRF in SillyTavern via SearXNG Search Proxy (CVE-2026-46372)
SillyTavern 1.17.0 and earlier have CVE-2026-46372, an SSRF in the SearXNG search proxy. FixVibe verified active scans flag deployments where the proxy can be used to fetch external URLs.
Authorization Plugin Bypass in Moby (CVE-2026-34040)
Moby/Docker Engine versions before 29.3.1 include an AuthZ plugin bypass fixed in 29.3.1. The issue matters for deployments that rely on authorization plugins, especially policies that inspect request bodies. FixVibe GitHub repo scans flag affected Moby Go dependencies.
Heap Buffer Overflow in NGINX ngx_http_rewrite_module (CVE-2026-42945)
CVE-2026-42945 affects NGINX Open Source and NGINX Plus release ranges when vulnerable rewrite-module configuration is loaded. FixVibe GitHub repo scans flag affected NGINX versions paired with matching rewrite configuration.
OS Command Injection and Data Exfiltration in gemini-mcp-tool (CVE-2026-0755)
gemini-mcp-tool versions 1.1.2 through 1.1.5 are affected by CVE-2026-0755 / GHSA-4h5r-5jm8-jxjm. FixVibe GitHub repo scans flag affected npm manifests and lockfiles and recommend upgrading to 1.1.6 or newer.
Mastra npm Package Scope Compromise via Stale Contributor Account
Security researchers described a Mastra npm scope compromise caused by stale publisher access. FixVibe GitHub repo scans flag easy-day-js manifest and lockfile matches associated with the compromised publish.
SQL Injection in Drupal Core (CVE-2026-9082)
Drupal Core CVE-2026-9082 affects several release lines, with vendor guidance tying the SQL-injection condition to PostgreSQL-backed sites. FixVibe GitHub repo scans flag affected drupal/core or drupal/core-recommended Composer evidence.
Command Injection in kill-port-process (CVE-2019-15609)
kill-port-process versions before 2.2.0 are affected by a command injection. FixVibe GitHub repo scans flag affected kill-port-process versions in npm manifests and lockfiles.
Uncontrolled Resource Consumption in Apache Tomcat (CVE-2020-11996)
Apache Tomcat release lines 8.5.0 through 8.5.55, 9.0.0.M1 through 9.0.35, and 10.0.0-M1 through 10.0.0-M5 are affected by CVE-2020-11996, a high-severity HTTP/2 resource-consumption advisory that can impact availability when the vulnerable runtime and connector are deployed.
Authentication Bypass in Paramiko SSH Server (CVE-2018-7750)
A critical Paramiko advisory affects SSH server-mode usage across several old release branches. FixVibe GitHub repo scans now report affected Python dependency evidence as a version-based advisory and recommend upgrading to the fixed branch release or newer.
Prototype Pollution in @andrei-tatar/nora-firebase-common (CVE-2024-30564)
A critical prototype-pollution advisory affects @andrei-tatar/nora-firebase-common versions 1.0.41 through 1.12.2. FixVibe GitHub repo scans now report affected dependency evidence as a version-based advisory and recommend upgrading to 1.12.3 or later.
Apache ActiveMQ Artemis Diagnostic Information Exposure (CVE-2023-50780)
Apache ActiveMQ Artemis allows authenticated users to access diagnostic information and controls through MBeans via Jolokia. FixVibe GitHub repo scans flag affected Artemis dependencies for CVE-2023-50780.
Unauthenticated Outbound Federation in Apache ActiveMQ Artemis (CVE-2026-27446)
Apache ActiveMQ Artemis CVE-2026-27446 affects outbound Core federation authentication boundaries. FixVibe GitHub repo scans flag affected artemis-server Maven and Gradle declarations.
Apache Spark UI Command Injection via ACL Impersonation (CVE-2022-33891)
Apache Spark UI releases in affected version ranges can allow command execution through ACL impersonation handling when vulnerable runtime conditions are present. FixVibe GitHub repo scans flag affected Apache Spark dependencies.
vLLM Remote Code Execution via Pickle Deserialization in AsyncEngineRPCServer
A critical vulnerability (CVE-2024-9053) in vLLM allows attackers to execute arbitrary code on the host machine. The issue stems from the use of Python's pickle module to deserialize data received through the AsyncEngineRPCServer entrypoints, which lacks sufficient validation of incoming payloads.
Type Confusion in YOURLS Leads to Unauthorized Resource Access
YOURLS (Your Own URL Shortener) versions prior to 1.7.4 contain a critical vulnerability where the application improperly handles resource access using incompatible types. This 'Type Confusion' flaw can be exploited by attackers to bypass intended access controls and interact with restricted system resources.
Critical XXE Vulnerability in http4k-format-xml (CVE-2024-55875)
The http4k-format-xml library is vulnerable to XML External Entity (XXE) injection. Attackers can exploit this by sending malicious XML payloads to applications using affected versions of the library, potentially leading to sensitive information disclosure, Server-Side Request Forgery (SSRF), and denial of service.
Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
A malicious Codex Remote UI npm package, codexui-android, steals AI tokens. FixVibe GitHub repo scans flag it in package manifests and lockfiles.
Typosquatted npm packages used to steal cloud and CI/CD secrets
FixVibe GitHub repo scans can flag manifests and lockfiles that resolve known Microsoft-reported npm typosquat package versions associated with cloud and CI/CD credential theft.
Miasma Campaign: Supply Chain Attack Targeting Red Hat npm Packages
The Miasma campaign compromised npm releases under the @redhat-cloud-services scope. FixVibe GitHub repo scans flag the known compromised package versions in manifests and lockfiles.
Securing CI/CD in an Agentic World: Claude Code GitHub Action Case
FixVibe GitHub repo scans flag Claude Code GitHub Action workflows with mutable action references, broad workflow token permissions, and risky access overrides.
Compromised Rust Crate 'onering' Performs Code Exfiltration
The Rust crate onering 1.4.1 was reported as compromised with build-time source-diff exfiltration behavior. FixVibe repo scans flag Cargo evidence for the malicious release or the compromised upstream git state.
Node-gyp Supply Chain Compromise: Self-Propagating npm Worm in binding.gyp
Security researchers have identified a supply chain compromise involving a self-propagating npm worm. The malicious payload is designed to hide within binding.gyp files, which are typically used by node-gyp for compiling native addon modules.
PickleScan ZIP Archive Scan Bypass (CVE-2025-10156)
PickleScan versions before 0.0.31 are affected by CVE-2025-10156, a ZIP archive scan bypass. FixVibe GitHub repo scans flag repositories that declare affected PickleScan versions.
Arbitrary Code Execution in Keras via Crafted Model Configuration Loading (CVE-2025-1550)
Keras versions 3.0.0 through 3.8.x can execute code while loading crafted .keras model archives. FixVibe GitHub repo scans flag affected Keras versions in Python dependency files.
Malware in @tanstack/arktype-adapter Exfiltrates Credentials (CVE-2026-45321)
The TanStack npm supply-chain compromise included @tanstack/arktype-adapter versions 1.166.12 and 1.166.15. These package versions contained embedded malware; teams should remove them, rebuild cached install environments, and rotate credentials if either version was installed.
Unauthenticated RCE in Langflow via Public Flow Build Endpoint (CVE-2026-33017)
Langflow 1.8.2 and earlier are associated with CVE-2026-33017 / GHSA-vwmf-pq79-vjvx. FixVibe verified active scans flag Langflow deployments that publicly report an affected version and guide teams to upgrade to 1.9.0 or newer.
Arbitrary Code Execution in NLTK via Zip Slip (CVE-2025-14009)
NLTK versions through 3.9.2 are associated with CVE-2025-14009, a downloader Zip Slip advisory that can lead to arbitrary code execution when malicious or compromised packages are extracted. Upgrade to 3.9.3 or newer.
Langflow CORS Misconfiguration Enables Account Takeover and RCE (CVE-2025-34291)
GitHub, NVD, and CISA describe CVE-2025-34291 as a critical Langflow CORS issue affecting versions 1.6.9 and earlier. FixVibe verified active scans flag exposed Langflow instances on an affected release that allow credentialed cross-origin requests.
Denial of Service in 'ws' Library via Excessive HTTP Headers (CVE-2024-37890)
Affected ws server deployments can crash when processing WebSocket upgrade requests with excessive HTTP headers. FixVibe GitHub repo scans flag affected ws versions in npm manifests and lockfiles.
SPIP XML Validator CSRF Advisory (CVE-2016-7980)
SPIP 3.1.2 and earlier are associated with a CSRF flaw in the XML validator workflow. FixVibe flags public SPIP sites that identify an affected release.
SQL Injection in TMT Lockcell (CVE-2023-3047)
TMT Lockcell before version 15 is affected by CVE-2023-3047 SQL injection. FixVibe verified active scans flag Lockcell login pages that behave as the advisory describes.
Remote Code Execution in Note Mark via Path Traversal (CVE-2026-44522)
Note Mark backend versions before 0.19.4 are affected by an asset-name path traversal issue that can impact administrator data exports. FixVibe GitHub repo scans flag affected Note Mark backend versions.
Cross-Site Request Forgery in Django (CVE-2011-0696)
Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 contain a CSRF handling flaw tracked as CVE-2011-0696 / GHSA-5j2h-h5hg-3wf8. FixVibe GitHub repo scans flag Python projects that pin or allow those Django versions.
WordPress REST API User Enumeration (CVE-2017-5487)
WordPress 4.7 before 4.7.1 exposed post-author data through the REST API. FixVibe verified active scans flag public WordPress REST user-slug exposure.
Command Injection in WebdriverIO BrowserStack Service (CVE-2026-25244)
WebdriverIO BrowserStack service versions up to and including 9.23.2 are affected by CVE-2026-25244 / GHSA-5c46-x3qw-q7j7. FixVibe repo scans flag affected @wdio/browserstack-service versions.
Prototype Pollution in deephas (CVE-2020-28271)
deephas versions 1.0.0 through 1.0.5 are affected by CVE-2020-28271, a prototype pollution. FixVibe GitHub repo scans flag affected deephas versions; runtime exploitability depends on whether untrusted object paths reach the package.
Directory Traversal in Gogs (CVE-2018-20303)
CVE-2018-20303 is a path traversal advisory affecting Gogs versions before 0.11.82.1218. Upgrade Gogs to 0.11.82.1218 or a build that includes commit ff93d9dbda5c; FixVibe GitHub repo scans flag affected Gogs versions in Go module files.
Arbitrary JavaScript Execution in PDF.js (CVE-2024-4367)
CVE-2024-4367 is a high-severity vulnerability in PDF.js (versions 4.1.392 and below) that allows attackers to execute arbitrary JavaScript. By rendering a malicious PDF, the library may execute embedded scripts, leading to potential XSS attacks and data exposure. Remediation involves upgrading to version 4.2.67 or later.
SQL Injection in Ghost Content API (CVE-2026-26980)
Ghost versions 3.24.0 through 6.19.0 contain a critical SQL injection vulnerability in the Content API. This allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to data exfiltration or unauthorized modifications.
Next.js Security Header Misconfiguration in next.config.js
Next.js applications using next.config.js for header management are susceptible to security gaps if path-matching patterns are imprecise. This research explores how wildcard and regex misconfigurations lead to missing security headers on sensitive routes and how to harden the configuration.
Detecting and Preventing Cross-Site Scripting (XSS) Vulnerabilities
Cross-Site Scripting (XSS) occurs when an application includes untrusted data in a web page without proper validation or encoding. This allows attackers to execute malicious scripts in the victim's browser, leading to session hijacking, unauthorized actions, and sensitive data exposure.
LiteLLM Proxy SQL Injection (CVE-2026-42208)
A critical SQL injection vulnerability (CVE-2026-42208) in LiteLLM's proxy component allows attackers to bypass authentication or access sensitive database information by exploiting the API key verification process.
Security Risks of Vibe Coding: Auditing AI-Generated Code
The rise of 'vibe coding'—building applications primarily through rapid AI prompting—introduces risks such as hardcoded credentials and insecure code patterns. Because AI models may suggest code based on training data containing vulnerabilities, their output must be treated as untrusted and audited using automated scanning tools to prevent data exposure.
JWT Security: Risks of Unsecured Tokens and Missing Claim Validation
JSON Web Tokens (JWTs) provide a standard for transferring claims, but security relies on rigorous validation. Failure to verify signatures, expiration times, or intended audiences allows attackers to bypass authentication or replay tokens.
Securing Vercel Deployments: Protection and Header Best Practices
This research explores security configurations for Vercel-hosted applications, focusing on Deployment Protection and custom HTTP headers. It explains how these features protect preview environments and enforce browser-side security policies to prevent unauthorized access and common web attacks.
Firebase Security Rules: Preventing Unauthorized Data Exposure
Firebase Security Rules are the primary defense for serverless applications using Firestore and Cloud Storage. When these rules are too permissive, such as allowing global read or write access in production, attackers can bypass intended application logic to steal or delete sensitive data. This research explores common misconfigurations, the risks of 'test mode' defaults, and how to implement identity-based access control.
CSRF Protection: Defending Against Unauthorized State Changes
Cross-Site Request Forgery (CSRF) remains a significant threat to web applications. This research explores how modern frameworks like Django implement protection and how browser-level attributes like SameSite provide defense-in-depth against unauthorized requests.
API Security Checklist: 12 Things to Check Before Going Live
APIs are the backbone of modern web applications but often lack the security rigor of traditional frontends. This research article outlines an essential checklist for securing APIs, focusing on access control, rate limiting, and cross-origin resource sharing (CORS) to prevent data breaches and service abuse.
API Key Leakage: Risks and Remediation in Modern Web Apps
Hard-coded secrets in frontend code or repository history allow attackers to impersonate services, access private data, and incur costs. This article covers the risks of secret leakage and the necessary steps for cleanup and prevention.
CORS Misconfiguration: Risks of Overly Permissive Policies
Cross-Origin Resource Sharing (CORS) is a browser mechanism designed to relax the Same-Origin Policy (SOP). While necessary for modern web apps, improper implementation—such as echoing the requester's Origin header or whitelisting the 'null' origin—can allow malicious sites to exfiltrate private user data.
Securing the MVP: Preventing Data Leaks in AI-Generated SaaS Apps
Rapidly developed SaaS applications often suffer from critical security oversights. This research explores how leaked secrets and broken access controls, such as missing Row Level Security (RLS), create high-impact vulnerabilities in modern web stacks.
Vulnerability Research: SSRF and Security Header Compliance
This research article examines Server-Side Request Forgery (SSRF) and the importance of HTTP security header compliance. Using insights from PortSwigger and Mozilla, we explore how automated scanning identifies these vulnerabilities and how FixVibe flags them.
SQL Injection: Preventing Unauthorized Database Access
SQL injection (SQLi) is a critical vulnerability where attackers interfere with an application's database queries. By injecting malicious SQL syntax, attackers can bypass authentication, view sensitive data like passwords and credit card details, or even compromise the underlying server.
Comparing Automated Security Scanners: Capabilities and Operational Risks
Automated security scanners are essential for identifying critical vulnerabilities such as SQL injection and XSS. However, they can inadvertently damage target systems through non-standard interactions. This research compares professional DAST tools with free security observatories and outlines best practices for safe automated testing.
Supabase Security Checklist: RLS, API Keys, and Storage
This research article outlines critical security configurations for Supabase projects. It focuses on the proper implementation of Row Level Security (RLS) to protect database rows, secure handling of anon and service_role API keys, and enforcing access control for storage buckets to mitigate risks of data exposure and unauthorized access.
OWASP Top 10 Checklist for 2026: Web App Risk Review
This research article provides a structured checklist for reviewing common web application security risks. By synthesizing the CWE Top 25 most dangerous software weaknesses with industry-standard access control and browser security guidelines, it identifies critical failure modes such as injection, broken authorization, and weak transport security that remain prevalent in modern development environments.
HTTP Security Headers: Implementing CSP and HSTS for Browser-Side Defense
This research explores the critical role of HTTP security headers, specifically Content Security Policy (CSP) and HTTP Strict Transport Security (HSTS), in protecting web applications from common vulnerabilities like Cross-Site Scripting (XSS) and protocol downgrade attacks.
CVE-2025-29927: Next.js Middleware Authorization Bypass
A critical vulnerability in Next.js allows attackers to bypass authorization checks implemented in middleware. By spoofing internal headers, external requests can masquerade as authorized sub-requests, leading to unauthorized access to protected routes and data.
