harbor.ist @harbor.ist · 29/09/2026Two new CVEs published today (as well as the fixed releases for them): `shell-quote`: www.cve.org/CVERecord?id... `pbkdf2`: www.cve.org/CVERecord?id... 011
harbor.ist @harbor.ist · 20/08/2025Harborist has published a new CVE: www.cve.org/CVERecord?id... This is on all versions v1.0.4 and below of the npmjs.com/cipher-base package. NOTE: this applies to all node and browser versions; please upgrade to v1.0.6 or later!cve.org 100
harbor.ist @harbor.ist · 18/07/2025Harborist has published a new CVE: www.cve.org/cverecord?id... This is on all versions of the npmjs.com/form-data package, on all node versions. Please note: node 18+ and all modern browsers (caniuse.com?search=formd...) have FormData built in - please consider migrating to it!npmjs.comform-dataA library to create readable 002
harbor.ist @harbor.ist · 23/06/2025Harborist has just published its first two CVEs: www.cve.org/CVERecord?id... www.cve.org/CVERecord?id... Both are on npmjs.com/pbkdf2, please update to v3.1.3!cve.org 001
Reposted by @harbor.istCommon Vulnerabilities and Exposures (CVE™) Program @cveprogram.bsky.social · 28/05/2025Harborist is now a CVE Numbering Authority (CNA) assigning CVE IDs for all projects listed under www.npmjs.com/~ljharb cve.org/Media/News/i... #cve #cna #vulnerability #vulnerabilitymanagement #cybersecurity 031