VulnScope — 以套件為主體的 CVE 查詢工具- HIGH7.8CVE-2026-54074@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
- HIGH7.5flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
- HIGH8.8CedarJava has policy injection vulnerability
- HIGH8.8CedarJava has type confusion vulnerability
- HIGH7.1OpenClaw: Workspace-derived service PATH could influence trash command selection
- HIGH7.1OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
- HIGH8.1OpenClaw: Discord allowFrom could bind to mutable display names
- HIGH7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
- HIGH7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
- HIGH8.1OpenClaw: Zalo allowFrom could bind to mutable display names
- HIGH8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
- HIGH7.5undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
- HIGH7.5http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
- HIGH8.1piscina: Prototype Pollution Gadget → RCE via inherited options.filename
- HIGH8.0Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`
- HIGH7.1OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
- HIGH8.1OpenClaw: Shell inline-command parsing could miss an allowlist check
- HIGH8.8OpenClaw: Pairing-scoped device session could restore revoked node token authority
- HIGH8.1OpenClaw: Host environment sanitizer missed two Node.js control variables
- HIGH7.5undici WebSocket client vulnerable to denial of service via fragment count bypass
- HIGH7.4undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
- LOW3.7undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
- LOW3.7undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
- HIGH7.5undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
- HIGH7.5HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS