VulnScope — package-centric CVE lookup- MEDIUM4.4CVE-2026-55650Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure
- HIGH7.5Langflow: Unauthenticated DoS through multipart form boundary file upload
- MEDIUM6.1Langflow: Logout button does not clear session
- MEDIUM6.1Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering
- MEDIUM6.2Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read
- MEDIUM6.8dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
- HIGH7.8@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
- HIGH7.5flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
- MEDIUM6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
- HIGH7.1jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
- HIGH7.5Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- HIGH7.6Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
- HIGH8.0py7zr: Arbitrary File Write Vulnerability
- HIGH7.3Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
- HIGH8.8CedarJava has policy injection vulnerability
- HIGH8.8CedarJava has type confusion vulnerability
- MEDIUM5.3NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
- MEDIUM5.3ts-deepmerge: Prototype Method Override leads to DoS
- MEDIUM5.8Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
- MEDIUM5.4OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
- HIGH7.1OpenClaw: Workspace-derived service PATH could influence trash command selection
- HIGH7.1OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
- HIGH8.1OpenClaw: Discord allowFrom could bind to mutable display names
- HIGH7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
- HIGH7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns