CVE-2026-2265 identifies an unauthenticated remote code execution (RCE) vulnerability in applications using Replicator npm package version 1.0.5. This flaw arises from insecure deserialization, allowing an attacker to execute arbitrary code by processing untrusted user input. With a Medium CVSS score of 6.5, the vulnerability has a network attack vector and low attack complexity, requiring no user interaction or privileges. Its potential impact, as per the CVSS vector, includes low confidentiality and integrity, with no availability impact. Although listed on the "Hot List," there is no indication of active exploitation (KEV) and no public exploit code available. Community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Replicator | Replicator | 1.0.5CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.