npm package
cyberchef
pkg:npm/cyberchef
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-57439 | Med | 5.0 | < 11.2.0 | 11.2.0 | Jul 8, 2026 | CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with operations such as Parse UDP to inject ma | |
| CVE-2026-42615 | Hig | 7.2 | < 11.0.0 | 11.0.0 | Apr 29, 2026 | GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring. | |
| CVE-2019-15532 | Med | 6.1 | < 8.31.3 | 8.31.3 | Aug 26, 2019 | CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs. |
- affected < 11.2.0fixed 11.2.0
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with operations such as Parse UDP to inject ma
- affected < 11.0.0fixed 11.0.0
GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.
- affected < 8.31.3fixed 8.31.3
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.