Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response body. When a typed-controller route handler returns anything other than a %Plug.Conn{}, dispatch/3 in… | |
| Aplazada | Media (6.3) | 0.68% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes. AshTypescript.TypedController.RequestHandler in lib/ash_typescript/typed_controller/request_handler.ex calls Ash.Type.cast_input/3… | |
| Aplazada | Baja (2.3) | 0.50% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, and the credentials attached to it, to an unintended route or an external origin. The URL builders in… | |
| Aplazada | Alta (8.2) | 0.50% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in original_value because embedded resources must… | |
| Aplazada | Media (6.3) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the configured error handler does not match. apply_error_handler/3 in lib/ash_typescript/rpc/errors.ex is the… | |
| Aplazada | Alta (8.2) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct field names. resolve_typed_struct_field/2 in lib/ash_typescript/rpc/field_processing/field_selector.ex… | |
| Aplazada | Alta (8.7) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied RPC field names. AshTypescript.FieldFormatter.convert_to_field_atom/2 in lib/ash_typescript/field_formatter.ex… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and templates/modular/procedure-call.ejs without escaping JavaScript template… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping before templates/base/enum-data-contract.ejs renders… | |
| Aplazada | Media (6.1) | 0.32% | — | Swagger-typescript-api Swagger Typescript APIAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl to fetch any http or https target without private IP, redirect, DNS rebinding,… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into the generated HttpClient baseUrl… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlled OpenAPI spec to… | |
| Aplazada | Alta (7.4) | 0.44% | — | Swagger-typescript-api Swagger Typescript APIAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to every URL fetched by fetchRemoteSchemaDocument while warmUpRemoteSchemasCache resolves external $ref URLs, allowing an… | |
| Aplazada | Media (4.7) | 0.20% | — | Utcp HttpAITypescript UtcpAI | 28/5/2026 | 21/7/2026 | typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. registerManual() validates the discovery URL against an HTTPS / loopback… | |
| Analizada | Media (4.8) | 0.13% | — | Anthropic Claude SDK FOR Typescript | 4/5/2026 | 17/6/2026 | Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.91.1, the BetaLocalFilesystemMemoryTool in the Anthropic TypeScript SDK created memory files and directories using the Node.js default modes (0o666 for files,… | |
| Analizada | Media (6.3) | 0.39% | — | Anthropic Claude SDK FOR Typescript | 31/3/2026 | 24/7/2026 | Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated model-supplied paths using a string prefix check that did not append a trailing… | |
| Aplazada | Media (5.4) | 0.30% | — | BSV Blockchain Typescript SDKAI | 18/2/2026 | 17/6/2026 | The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version 2.0.0, a cryptographic vulnerability in the TypeScript SDK's BRC-104 authentication implementation caused incorrect signature data preparation, resulting in signature incompatibility between SDK… | |
| Modificada | Alta (7.1) | 0.38% | — | Lfprojects MCP Typescript SDK | 4/2/2026 | 15/7/2026 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport… | |
| Analizada | Alta (8.7) | 0.44% | — | Lfprojects MCP Typescript SDK | 5/1/2026 | 14/7/2026 | Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI matching contains nested quantifiers that can… | |
| Analizada | Alta (7.6) | 0.51% | — | Lfprojects MCP Typescript SDK | 2/12/2025 | 17/6/2026 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with… | |
| Modificada | Alta (7.1) | 0.59% | — | Sequelizejs Sequelize-typescript | 24/11/2023 | 17/6/2026 | Prototype Pollution in GitHub repository robinbuschmann/sequelize-typescript prior to 2.1.6. | |
| Modificada | Crítica (9.8) | 1.8% | — | Typescript Deep Merge Project Typescript Deep Merge | 9/8/2022 | 17/6/2026 | The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function. | |
| Modificada | Alta (8.8) | 5.9% | — | Microsoft Azure Storage ExplorerMicrosoft TypescriptMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+1 | 14/7/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'. |