Monkeytype is a typing-practice and performance-tracking web application with a community-driven focus, and its observed vulnerability surface centers on web application input handling. The recurring weakness classes—cross-site scripting, code injection, and injection-type flaws—reflect the challenges of safely processing user input and rendering dynamic content in a browser-based environment. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Monkeytype over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41127CRITICAL Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-failure-comment.yml GitHub Workf | Aug 2, 2024 | 9.6 | 27 | NO | NO |
CVE-2025-59838MEDIUM Monkeytype is a minimalistic and customizable typing test. In versions 25.36.0 and prior, improper handling of user input when loading a saved custom text results in XSS. This issu | Sep 25, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-66563MEDIUM Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute malicious javascript | Dec 4, 2025 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Monkeytype.
Media articles that mention a CVE ID that affects a product developed by Monkeytype — matched by CVE ID, not by vendor name.