VYPR

Qinglong

by Whyour

Source repositories

CVEs (2)

  • CVE-2026-3965MedMar 12, 2026
    risk 0.34cvss 6.3epss 0.00

    A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file back/loaders/express.ts of the component API Interface. The manipulation of the argument command leads to protection mechanism failure. The attack may be…

  • CVE-2026-55445CriJul 15, 2026
    risk 0.00cvss epss 0.00

    Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts checks /api/user/init but not /open/user/init, while rewrite('/open/*', '/api/$1') rewrites the whitelisted…