VYPR

Codex

by Codex

Source repositories

CVEs (3)

  • CVE-2021-43635MedFeb 4, 2022
    risk 0.40cvss 6.1epss 0.02

    A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malicious users to execute arbitrary code via a crafted http code in a .json file.

  • CVE-2026-17497HigJul 26, 2026
    risk 0.00cvss 8.3epss 0.00

    NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run…

  • CVE-2026-17496HigJul 26, 2026
    risk 0.00cvss 8.1epss 0.00

    NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model…