VYPR
High severity7.5NVD Advisory· Published Sep 8, 2023· Updated Jun 17, 2026

CVE-2023-39584

CVE-2023-39584

Description

Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
hexonpm
< 7.2.07.2.0

Affected products

4
  • Hexo/Hexo3 versions
    cpe:2.3:a:hexo:hexo:*:*:*:*:*:node.js:*:*+ 2 more
    • cpe:2.3:a:hexo:hexo:*:*:*:*:*:node.js:*:*range: <=6.3.0
    • cpe:2.3:a:hexo:hexo:7.0.0:rc1:*:*:*:node.js:*:*
    • cpe:2.3:a:hexo:hexo:7.0.0:rc2:*:*:*:node.js:*:*
  • ghsa-coords
    Range: < 7.2.0

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.