Duffel operates a modestly scoped API and travel-commerce platform, with its disclosed vulnerability footprint concentrated in the Paginator component. The observed weakness involves improper control of code generation, a class of flaw that arises in dynamic code contexts and can carry significant consequence if an attacker can influence the generated code path. Current severity, exploitation activity, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Duffel over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15150CRITICAL There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to the paginate() function. This w | Sep 1, 2020 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Duffel.
Media articles that mention a CVE ID that affects a product developed by Duffel — matched by CVE ID, not by vendor name.