CWE-201

CWE-201 · 3 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-201, highest CVSS first.

  1. HIGH 7.5CVE-2026-66901public PoC

    Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hosts were not checked a…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.4CVE-2026-101043public PoC

    pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled and the pr…

    AI risk analysis on Exploit-DB.ai →

  3. LOW 3.4CVE-2026-63630public PoC

    BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON without schema or destination validation. When a user imports the crafted workflow and runs …

    AI risk analysis on Exploit-DB.ai →