VYPR
Vendor

Omnivore App

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-82454CriAug 29, 2026
    risk 0.52cvss 9.1epss 0.00

    The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to…

  • CVE-2026-77067MedAug 20, 2026
    risk 0.26cvss 5.0epss 0.00

    The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/src/jobs/call_webhook.ts issues…

  • CVE-2026-77066MedAug 20, 2026
    risk 0.26cvss 5.0epss 0.00

    The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved…