VYPR

auto-changelog

by Cookpete

CVEs (1)

  • CVE-2026-12171HigOct 5, 2026
    risk 0.44cvss 7.8epss —

    auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to…