update_disk_psu_baseline.sh requires password in plain text
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Deno: Miller-Rabin Primality Test Allows Zero Rounds
Deno: Command Injection via spawnSync & spawn on Windows
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
Deno: WebSocket API sandbox bypass via missing post-DNS check
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
n8n: Merge Node SQL Mode Prototype Pollution
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
n8n: Same-Origin XSS in Respond to Webhook Node
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
n8n: Git Node Clone and Push Operations Bypass File Sandbox
n8n: Python sandbox escape
vLLM: OpenAI auth bypass
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read