Browse all 6 CVE security advisories affecting ljharb. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-107353 | traverse: set() can write to built-in prototypes via an untrusted path — traverse CWE-1321 | 6.5 | Medium | 2026-10-07 |
| CVE-2026-82562 | qs.parse does not enforce arrayLimit on comma groups under bracket-push keys when throwOnLimitExceeded is set (incomplete fix for CVE-2026-2391) — qs CWE-770 | 3.7 | Low | 2026-08-29 |
| CVE-2026-82417 | qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property — qs CWE-248 | 5.3 | Medium | 2026-08-29 |
| CVE-2026-13311 | shell-quote parse() is quadratic in token count, enabling denial of service — shell-quote CWE-407 | 7.5 | High | 2026-06-25 |
| CVE-2026-8723 | qs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnly — qs CWE-476 | 5.3 | Medium | 2026-05-16 |
| CVE-2022-0841 | OS Command Injection in ljharb/npm-lockfile — ljharb/npm-lockfile CWE-78 | 9.8 | - | 2022-03-03 |
This page lists every published CVE security advisory associated with ljharb. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.