The Lab · 2026-03-25 16:27:22 · GitHub Issues
A critical remote code execution vulnerability, tracked as CVE-2025-54782, has triggered an urgent security remediation effort within Databricks. The flaw, rated as Critical, resides in the `@nestjs/devtools-integration` component (version <=0.2.0) used by the `databricks-plan-optimizer`. The vulnerability's mechanism ...
The Lab · 2026-04-26 06:54:06 · GitHub Issues
A critical security gap has been identified in the application's error handling infrastructure. The backend service running on NestJS lacks a globally registered exception filter, leaving internal system details exposed to any API consumer when unhandled errors occur. This is not merely a development inconvenience — it...
The Lab · 2026-04-27 22:54:09 · GitHub Issues
The NestJS team has released an urgent security patch addressing a critical injection vulnerability in @nestjs/core. The flaw, tracked as CVE-2026-35515 and catalogued under GHSA-36xv-jgw5-4q75, involves the improper neutralization of special elements in output used by a downstream component. The vulnerability affects ...