Loading market data...
← Back to CVE feed

CVE-2026-2265

MEDIUM CVSS 6.5 View on NVD ↗

Description

An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Published: Apr 01, 2026 17:28 UTC Modified: Apr 01, 2026 20:16 UTC