Skip to content
Noroxi

monkeytype records

3 published records for vendor monkeytype.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
66.7%
Median publish → KEV
No record has entered KEV

Records by year

  1. 24
  2. 25

Bar: total · dark part: CISA KEV.

Attack profile

All records

3 records
  • Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its `ci-failure-comment.yml` GitHub Workflow, enabling attackers to gain `pull

    CriticalCVSS 9.6Proof of conceptEPSS 1%

    monkeytype · monkeytypeAug 2, 2024

  • Monkeytype vulnerable to stored XSS in approve quotes page

    HighCVSS 7.1No exploitEPSS 0%

    monkeytype · monkeytypeDec 4, 2025

  • Monkeytype Vulnerable to Self-XSS on loading saved custom text

    LowCVSS 2.4No exploitEPSS 0%

    monkeytype · monkeytypeSep 25, 2025