The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,688
Mitigations16,877
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
deepseek-tui>= 0.8.6, < 0.8.41
NPM: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
7.8
18 minutes ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
7.8
18 minutes ago
deepseek-tui>= 0.8.33, < 0.8.41
NPM: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
7.8
20 minutes ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
7.8
20 minutes ago
deepseek-tui>= 0.3.27, < 0.8.41
NPM: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
7.4
20 minutes ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
7.4
20 minutes ago
deepseek-tui>= 0.8.5, < 0.8.41
TOCTOU on DNS failure for DNS pinning
8.6
27 minutes ago
codewhale>= 0.8.41, < 0.8.64
TOCTOU on DNS failure for DNS pinning
8.6
27 minutes ago
deepseek-tui>= 0.8.32, < 0.8.41
NPM: CodeWhale: js_execution leaks parent environment to model context via missing env scrub
7.5
29 minutes ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: js_execution leaks parent environment to model context via missing env scrub
7.5
29 minutes ago
deepseek-tui>= 0.3.27, < 0.8.41
NPM: CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
9.3
29 minutes ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
9.3
29 minutes ago
deepseek-tui>= 0.3.10, < 0.8.41
NPM: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
7
30 minutes ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
7
30 minutes ago
deepseek-tui>= 0.8.8, < 0.8.41
NPM: CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
7.5
31 minutes ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
7.5
31 minutes ago
deepseek-tui>= 0.8.32, < 0.8.41
NPM: CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
7.5
57 minutes ago
codewhale>= 0.8.41, < 0.8.64
NPM: CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
7.5
57 minutes ago
@simplewebauthn/server<= 13.3.1
NPM: SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
2
58 minutes ago
Restaurant Menu by MotoPress< 2.4.12
Unauthenticated Payment Bypass vulnerability
5.3
5 hours ago