Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
HIGH 8.4
CVE-2023-46115
Tauri's Updater Private Keys Possibly Leaked via Vite Environment Variables
HIGH 8.8
CVE-2023-4863
libwebp: OOB write in BuildHuffmanTable
HIGH 7.4
CVE-2026-75912
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
HIGH 8.6
CVE-2026-75856
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
HIGH 7.8
CVE-2026-75911
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
HIGH 7.5
CVE-2026-75859
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
HIGH 7.8
CVE-2026-75858
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
HIGH 7.5
CVE-2026-75915
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
HIGH 7.0
CVE-2026-75857
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
HIGH 7.5
CVE-2026-75914
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
HIGH 7.2
CVE-2021-32629
Memory access due to code generation flaw in Cranelift module
HIGH 7.5
CVE-2026-42559
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
HIGH 7.4
CVE-2026-45310
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
HIGH 7.5
CVE-2024-43414
Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries
Ready to move
Start Securing
Free, no credit card | First findings in minutes