VulnScope — 以套件為主體的 CVE 查詢工具- MEDIUM4.4CVE-2026-55650Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure
- MEDIUM6.1Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering
- MEDIUM6.2Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read
- HIGH7.8@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
- HIGH7.5flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
- HIGH8.8CedarJava has policy injection vulnerability
- HIGH8.8CedarJava has type confusion vulnerability
- MEDIUM5.3NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
- MEDIUM5.3ts-deepmerge: Prototype Method Override leads to DoS
- MEDIUM5.8Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
- MEDIUM5.4OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
- HIGH7.1OpenClaw: Workspace-derived service PATH could influence trash command selection
- HIGH7.1OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
- HIGH8.1OpenClaw: Discord allowFrom could bind to mutable display names
- HIGH7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
- HIGH7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
- MEDIUM4.2OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
- MEDIUM6.5OpenClaw: memory-wiki shared search could miss session visibility checks
- MEDIUM5.5OpenClaw: Config recovery could restore openclaw.json with broad file permissions
- HIGH8.1OpenClaw: Zalo allowFrom could bind to mutable display names
- MEDIUM4.3OpenClaw: Skill-command dispatch could skip before-tool-call hooks
- MEDIUM6.1OpenClaw: Exported session HTML could keep unsafe markdown links
- MEDIUM5.3OpenClaw: Slack reaction events could ignore reaction notification settings
- MEDIUM4.2OpenClaw: Bootstrap token replay could widen pending pairing scopes
- HIGH8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks