VYPR
Vendor

Codex

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2021-43635MedFeb 4, 2022
    risk 0.40cvss 6.1epss 0.02

    A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malicious users to execute arbitrary code via a crafted http code in a .json file.

  • CVE-2022-23474MedDec 15, 2022
    risk 0.33cvss 6.1epss 0.01

    Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes pasted input into wrapper’s innerHTML. This issue is patched in version 2.26.0.

  • CVE-2026-17497HigJul 26, 2026
    risk 0.00cvss 8.3epss 0.00

    NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run…

  • CVE-2026-17496HigJul 26, 2026
    risk 0.00cvss 8.1epss 0.00

    NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model…