Topics /

Supply chain

Packages, CI/CD and dev tools compromised and spread through dependencies

Vulnerability · KEV
CVE-2026-90553
vLLM LlavaOnevision2 ignores trust_remote_code
High7.8Not listed2026-07-11
CVE-2026-82021
Hermes Agent MCP catalog not pinned to a commit
Supply chainAI securityUnpinned dependency
Critical9.0Not listed2026-07-07
CVE-2026-50016
pnpm dependency alias path traversal
Supply chainPath traversal
High8.8Not listed
CVE-2026-48501
GitHub CLI verify commands leak token
Supply chainCredential exposure
Critical9.1Not listed
CVE-2026-45321
TanStack npm release pipeline hijack
Supply chainAI securityMalicious code injection
Critical9.6Listed2026-05-11
CVE-2026-45758
guardrails-ai malicious PyPI release
Supply chainAI securityMalicious code injection
Critical9.6Not listed2026-05-11
No CVEGHSA-fw8c-xr5c-95f9
axios npm maintainer account takeover
Supply chainMalicious code injection
N/ANot listed2026-03-31
CVE-2026-33634
Trivy and trivy-action trojanized
Supply chainAI securityMalicious code injection
High8.8Listed2026-03-19
CVE-2026-5241
Transformers LightGlue config overrides trust_remote_code
Critical9.6Not listed2025-07-25
CVE-2026-12537
Gemini CLI headless workspace trust
High7.8Not listed2025-06-25