VYPR
Medium severity5.4OSV Advisory· Published Oct 7, 2021· Updated Jun 17, 2026

CVE-2021-23447

CVE-2021-23447

Description

This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
teddynpm
< 0.5.90.5.9

Affected products

3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.