VulnScope — 以套件為主體的 CVE 查詢工具- —CVE-2026-50556@angular/platform-server: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR
- —CVE-2026-50555@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- —node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
- —launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
- —vite: `server.fs.deny` bypass on Windows alternate paths
- MEDIUM5.3JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
- LOW3.2@babel/core: Arbitrary File Read via sourceMappingURL Comment
- —@angular/service-worker: Request Credential & Cache Policy Stripping
- —@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
- —@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
- —@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)
- —Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
- —@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass
- HIGH8.2tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
- HIGH7.5ws: Memory exhaustion DoS from tiny fragments and data chunks
- —Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
- MEDIUM5.4Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
- HIGH7.5form-data: CRLF injection in form-data via unescaped multipart field names and filenames
- HIGH8.1Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
- HIGH7.5Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
- CRITICAL9.0Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
- —Budibase: Unvalidated VectorDB Host Parameter Enables SSRF
- MEDIUM6.5Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
- HIGH7.7Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
- —Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step