Growthbook is an open-source feature-flag and experimentation platform whose vulnerability footprint centers on path-traversal weaknesses in its core product, reflecting typical input-validation risks in web-based configuration and file-handling logic. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Growthbook over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36065HIGH GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in versions prior to 2022-08-29, attackers can register new account | Sep 6, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Growthbook.
Media articles that mention a CVE ID that affects a product developed by Growthbook — matched by CVE ID, not by vendor name.