Harborist
First CVE: Jun 23, 2025Active for: 1 year
12
CVEs Published
More CVEs Published than 30% of tracked CNAs
6.0
Avg CVEs / Year
More Avg CVEs / Year than 37% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 62% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Harborist over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 23, 2025
12 months ago
Most Recent CVE
Jul 15, 2026
9 days ago
Top CVEs
All CVEs published by Harborist as a CNA, regardless of affected vendor or product.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9277HIGH shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character usi | May 22, 2026 | 8.1 | 38 | NO | NO |
CVE-2026-13311HIGH shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every i | Jun 25, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-12143HIGH form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concate | Jun 12, 2026 | 7.5 | 36 | NO | NO |
CVE-2025-9288CRITICAL Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11. | Aug 20, 2025 | 9.1 | 33 | NO | NO |
CVE-2025-9287CRITICAL Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4. | Aug 20, 2025 | 9.1 | 31 | NO | NO |
CVE-2025-7783CRITICAL Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.
This is | Jul 18, 2025 | 9.4 | 31 | NO | NO |
CVE-2026-8723MEDIUM ### Summary
`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is syn | May 17, 2026 | 5.3 | 27 | NO | NO |
CVE-2026-2391HIGH ### Summary
The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory | Feb 12, 2026 | 7.5 | 27 | NO | NO |
CVE-2025-6547CRITICAL Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2. | Jun 23, 2025 | 9.1 | 27 | NO | NO |
CVE-2025-6545CRITICAL Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js.
This issu | Jun 23, 2025 | 9.1 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA12 CVEs
17%
8%
33%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (66.7%)
High4 (33.3%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (100.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Harborist as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Harborist as a CNA — matched by CVE ID, not by organization name.