VYPR

Cyberchef

by Gchq

npm: cyberchef

Source repositories

CVEs (4)

  • CVE-2026-42615HigApr 29, 2026
    risk 0.40cvss 7.2epss 0.00

    GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.

  • CVE-2019-15532MedAug 26, 2019
    risk 0.33cvss 6.1epss 0.01

    CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.

  • CVE-2026-72912MedAug 10, 2026
    risk 0.21cvss 4.3epss 0.00

    CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters…

  • CVE-2026-57439MedJul 8, 2026
    risk 0.00cvss 5.0epss 0.00

    CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with operations such as Parse UDP to inject…