orpc records
2 published records for vendor orpc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-28794No exploit | oRPC: Prototype Pollution in `@orpc/client` via `StandardRPCJsonSerializer` Deserializationorpc · orpc · CWE-1321 | Critical9.3 | — | 1.1% | Mar 6, 2026 |
21Monitor | CVE-2026-33331Proof of concept | oRPC: Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringifyorpc · orpc · CWE-79 | Medium5.4 | — | 0.3% | Mar 24, 2026 |
- CVE-2026-2879437Monitor
oRPC: Prototype Pollution in `@orpc/client` via `StandardRPCJsonSerializer` Deserialization
CriticalCVSS 9.3No exploitEPSS 1%orpc · orpcMar 6, 2026
- CVE-2026-3333121Monitor
oRPC: Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify
MediumCVSS 5.4Proof of conceptEPSS 0%orpc · orpcMar 24, 2026