CWE-201
CWE-201 · 3 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-201, highest CVSS first.
- HIGH 7.5CVE-2026-66901public PoC
Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hosts were not checked a…
- HIGH 7.4CVE-2026-101043public PoC
pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled and the pr…
- LOW 3.4CVE-2026-63630public PoC
BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON without schema or destination validation. When a user imports the crafted workflow and runs …