Cyberchef
by Gchq
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-42615 | Hig | 0.40 | 7.2 | 0.00 | Apr 29, 2026 | GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring. | ||
| CVE-2019-15532 | Med | 0.33 | 6.1 | 0.01 | Aug 26, 2019 | CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs. | ||
| CVE-2026-72912 | Med | 0.21 | 4.3 | 0.00 | Aug 10, 2026 | CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters… | ||
| CVE-2026-57439 | Med | 0.00 | 5.0 | 0.00 | Jul 8, 2026 | CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with operations such as Parse UDP to inject… |
- risk 0.40cvss 7.2epss 0.00
GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.
- risk 0.33cvss 6.1epss 0.01
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
- risk 0.21cvss 4.3epss 0.00
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters…
- risk 0.00cvss 5.0epss 0.00
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with operations such as Parse UDP to inject…