unjs records
6 published records for vendor unjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-184 Incomplete List of Disallowed Inputs1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-69874No exploit | nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary fiunjs · nanotar · CWE-22 | Critical9.8 | — | 0.9% | Feb 11, 2026 |
30Monitor | CVE-2026-35209No exploit | defu: Prototype pollution via `__proto__` key in defaults argumentunjs · defu · CWE-1321 | High7.5 | — | 0.5% | Apr 6, 2026 |
27Monitor | CVE-2025-54387No exploit | IPX is Vulnerable to Path Traversal via Prefix Matching Bypassunjs · ipx · CWE-22 | Medium6.9 | — | 0.7% | Aug 4, 2025 |
24Monitor | CVE-2026-39315No exploit | Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()unjs · unhead · CWE-184 | Medium6.1 | — | 0.3% | Apr 9, 2026 |
24Monitor | CVE-2026-31873No exploit | Unhead has a Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivityunjs · unhead · CWE-79 | Medium6.1 | — | 0.3% | Mar 12, 2026 |
21Monitor | CVE-2026-31860No exploit | Unhead has a XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol checkunjs · unhead · CWE-79 | Medium5.3 | — | 0.3% | Mar 12, 2026 |
- CVE-2025-6987439Monitor
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary fi
CriticalCVSS 9.8No exploitEPSS 1%unjs · nanotarFeb 11, 2026
- CVE-2026-3520930Monitor
defu: Prototype pollution via `__proto__` key in defaults argument
HighCVSS 7.5No exploitEPSS 1%unjs · defuApr 6, 2026
- CVE-2025-5438727Monitor
IPX is Vulnerable to Path Traversal via Prefix Matching Bypass
MediumCVSS 6.9No exploitEPSS 1%unjs · ipxAug 4, 2025
- CVE-2026-3931524Monitor
Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()
MediumCVSS 6.1No exploitEPSS 0%unjs · unheadApr 9, 2026
- CVE-2026-3187324Monitor
Unhead has a Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity
MediumCVSS 6.1No exploitEPSS 0%unjs · unheadMar 12, 2026
- CVE-2026-3186021Monitor
Unhead has a XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check
MediumCVSS 5.3No exploitEPSS 0%unjs · unheadMar 12, 2026