VYPR

pass

by Pass

CVEs (2)

  • CVE-2025-67397CriJan 5, 2026
    risk 0.59cvss 9.1epss 0.01

    An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specific payload injection.

  • CVE-2020-28086HigDec 9, 2020
    risk 0.49cvss 7.5epss 0.01

    pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the password. If an attacker controls the central Git server or one of the other…