Skip to content
Noroxi

unjs records

6 published records for vendor unjs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
83.3%
Median publish → KEV
No record has entered KEV

All records

6 records
  • nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary fi

    CriticalCVSS 9.8No exploitEPSS 1%

    unjs · nanotarFeb 11, 2026

  • defu: Prototype pollution via `__proto__` key in defaults argument

    HighCVSS 7.5No exploitEPSS 1%

    unjs · defuApr 6, 2026

  • IPX is Vulnerable to Path Traversal via Prefix Matching Bypass

    MediumCVSS 6.9No exploitEPSS 1%

    unjs · ipxAug 4, 2025

  • Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()

    MediumCVSS 6.1No exploitEPSS 0%

    unjs · unheadApr 9, 2026

  • Unhead has a Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity

    MediumCVSS 6.1No exploitEPSS 0%

    unjs · unheadMar 12, 2026

  • Unhead has a XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check

    MediumCVSS 5.3No exploitEPSS 0%

    unjs · unheadMar 12, 2026