Gatsbyjs develops a static site generation framework and plugin ecosystem for building web applications, with its core product and source plugins such as gatsby-source-wordpress forming the primary focus of observed vulnerabilities. The recurring weakness classes—path traversal, untrusted deserialization, information exposure, input validation flaws, and cross-site scripting—reflect the framework's role in processing user-supplied data and managing file access during build and rendering operations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gatsbyjs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25863CRITICAL The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, | Jun 10, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-32770HIGH Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authentication variables into the app.j | Jul 15, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-22491MEDIUM Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 pas | Jan 13, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-34238MEDIUM Gatsby is a free and open source framework based on React. The Gatsby framework prior to versions 4.25.7 and 5.9.1 contain a Local File Inclusion vulnerability in the `__file-code- | Jun 8, 2023 | 5.3 | 18 | NO | NO |
CVE-2023-30548MEDIUM gatsby-plugin-sharp is a plugin for the gatsby framework which exposes functions built on the Sharp image processing library. The gatsby-plugin-sharp plugin prior to versions 5.8.1 | Apr 17, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gatsbyjs.
Media articles that mention a CVE ID that affects a product developed by Gatsbyjs — matched by CVE ID, not by vendor name.