The Lab · 2026-03-26 01:27:31 · GitHub Issues
A critical security vulnerability has been flagged within the widely-used `flatted` npm package, necessitating an immediate upgrade to version 3.4.2. The issue centers on a potential prototype pollution flaw in older versions, a class of vulnerability that can allow attackers to modify an application's object prototype...
The Lab · 2026-03-27 15:27:25 · GitHub Issues
A critical security vulnerability has been identified in the widely used Model Context Protocol (MCP) TypeScript SDK, tracked as CVE-2025-66414. The flaw stems from the SDK's default configuration, which fails to enable DNS rebinding protection, leaving any application built upon it potentially exposed to a classic net...
The Lab · 2026-03-31 14:27:25 · GitHub Issues
A critical vulnerability in a core cryptographic library has been patched, exposing a subtle but significant flaw in a widely used elliptic curve. Cloudflare's CIRCL library, version 1.6.3, fixes a bug in its P-384 (secp384r1) curve implementation where the `CombinedMult` function could produce mathematically incorrect...
The Lab · 2026-04-08 00:27:09 · GitHub Issues
A critical security vulnerability in the Angular development platform exposes applications to cross-site scripting (XSS) attacks. The flaw, tracked as CVE-2026-32635, resides in the Angular runtime and compiler. It allows attackers to bypass the framework's built-in sanitization mechanism when an application uses a sec...
The Lab · 2026-04-11 10:22:33 · GitHub Issues
A critical security alert has been issued for the widely-used Axios HTTP client library, mandating an immediate update to version 1.x. The alert, triggered by automated dependency management, flags two significant vulnerabilities (CVE-2021-3749 and CVE-2023-45857) present in older versions. This is not a routine patch;...
The Lab · 2026-04-19 11:22:33 · GitHub Issues
A critical security vulnerability in the PHPUnit testing framework has triggered an urgent dependency update across countless PHP projects. The flaw, tracked as GHSA-qrr6-mg7r-m243, necessitates an immediate upgrade from PHPUnit versions prior to 13.1.6. This is not a routine patch; the explicit [SECURITY] tag on the p...