Elysiajs is a TypeScript-based web framework whose vulnerability footprint concentrates in its core Elysia product, with recurring signal around dynamic code handling and input-processing weaknesses including prototype pollution, code injection, and inefficient regex complexity. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elysiajs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66456CRITICAL Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype po | Dec 9, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-66457HIGH Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.17 and below are subject to arbitrary c | Dec 9, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-30837HIGH Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: 'url' }) is vul | Mar 10, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-31865MEDIUM Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to version 1.4.27, an Elysia cookie can be ov | Mar 18, 2026 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elysiajs.
Media articles that mention a CVE ID that affects a product developed by Elysiajs — matched by CVE ID, not by vendor name.