Mend, a software composition analysis and supply-chain security vendor, maintains a focused product line with a narrow disclosed vulnerability footprint centered on its CureKit offering. The vendor's observed exposure reflects path-traversal weaknesses characteristic of file-handling and directory-access functionality in security tooling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mend (formerly WhiteSource) over time
Of all the CVEs published by Mend (formerly WhiteSource) as a CNA, 0.7% affect products that Mend (formerly WhiteSource) develops as a vendor.
Of all the CVEs published that affect products developed by Mend (formerly WhiteSource), 100.0% are self-published by Mend (formerly WhiteSource) as a CNA.
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23082HIGH In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal. | May 31, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mend (formerly WhiteSource).
Media articles that mention a CVE ID that affects a product developed by Mend (formerly WhiteSource) — matched by CVE ID, not by vendor name.