Morgan Project maintains a narrowly scoped product portfolio centered around the Morgan tool, with observed vulnerabilities clustering around injection-class weaknesses including code injection, command injection, and improper output handling in logging contexts. These patterns reflect typical attack surfaces in command-line and scripting utilities where untrusted input traverses code generation or system execution boundaries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Morgan Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5413CRITICAL An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1. | Mar 21, 2019 | 9.8 | 31 | NO | NO |
CVE-2026-5078MEDIUM Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizi | Jun 3, 2026 | 5.3 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Morgan Project.
Media articles that mention a CVE ID that affects a product developed by Morgan Project — matched by CVE ID, not by vendor name.