Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 8.4
crates.io

CVE-2023-46115

Tauri's Updater Private Keys Possibly Leaked via Vite Environment Variables

HIGH 8.8
crates.io KEV

CVE-2023-4863

libwebp: OOB write in BuildHuffmanTable

HIGH 7.4
crates.io

CVE-2026-75912

CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval

HIGH 8.6
crates.io

CVE-2026-75856

CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning

HIGH 7.8
crates.io

CVE-2026-75911

CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

HIGH 7.5
crates.io

CVE-2026-75859

CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository

HIGH 7.8
crates.io

CVE-2026-75858

CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

HIGH 7.5
crates.io

CVE-2026-75915

CodeWhale: js_execution leaks parent environment to model context via missing env scrub

HIGH 7.0
crates.io

CVE-2026-75857

CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)

HIGH 7.5
crates.io

CVE-2026-75914

CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes

HIGH 7.2
crates.io

CVE-2021-32629

Memory access due to code generation flaw in Cranelift module

HIGH 7.5
crates.io

CVE-2026-42559

dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport

HIGH 7.4
crates.io

CVE-2026-45310

DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool

HIGH 7.5
crates.io

CVE-2024-43414

Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries

Ready to move

Start Securing

Free, no credit card | First findings in minutes