VYPR

repomix

by Yamadashy

CVEs (4)

  • CVE-2026-49987Jul 15, 2026
    risk 0.00cvss epss 0.01

    Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly to git fetch and git checkout without validation or --end-of-options, allowing --upload-pack or other Git…

  • CVE-2026-49988Jul 15, 2026
    risk 0.00cvss epss 0.00

    Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_output flow can register and read arbitrary local .json, .txt, .md, or .xml files without the file_system_read_file runSecretLint()…

  • CVE-2026-59702Jul 8, 2026
    risk 0.00cvss epss 0.00

    repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file:// URLs before passing them to git clone,…

  • CVE-2026-59703Jul 8, 2026
    risk 0.00cvss epss 0.00

    repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteValue function in src/core/git/gitRemoteParse.ts fails to block file:// URLs, permitting attackers to…