VYPR
Vendor

Projen

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-89066HigSep 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters…

  • CVE-2026-89065HigSep 11, 2026
    risk 0.39cvss 7.1epss 0.00

    Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted…

  • CVE-2021-21423MedApr 6, 2021
    risk 0.37cvss 6.8epss 0.01

    `projen` is a project generation tool that synthesizes project configuration files such as `package.json`, `tsconfig.json`, `.gitignore`, GitHub Workflows, `eslint`, `jest`, and more, from a well-typed definition written in JavaScript. Users of projen's `NodeProject` project…