VulnScope — 以套件為主體的 CVE 查詢工具- —CVE-2026-54279aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
- —aiohttp: CRLF injection in multipart headers
- LOW3.1React Router: Potential CSRF via PUT/PATCH/DELETE document requests
- CRITICAL9.8Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
- —DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
- MEDIUM6.1DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
- MEDIUM6.1DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
- HIGH7.5protobufjs: Denial of service through unbounded Any expansion during JSON conversion
- MEDIUM5.3protobufjs : Schema-derived names can shadow runtime-significant properties
- —@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
- —@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
- —@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
- —@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)
- —Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
- —@angular/platform-server: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR
- —@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- —node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
- —launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
- —vite: `server.fs.deny` bypass on Windows alternate paths
- MEDIUM5.3JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
- LOW3.2@babel/core: Arbitrary File Read via sourceMappingURL Comment
- —@angular/service-worker: Request Credential & Cache Policy Stripping
- —@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
- —@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
- —@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)