NPR's vulnerability profile centers on pym.js, a focused JavaScript library used for embedding and cross-domain communication in web applications. The observed weakness class involves cross-site request forgery, reflecting the library's role in handling cross-origin requests and the associated token-validation demands of embedded content. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Npr over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000086HIGH NPR Visuals Team Pym.js version versions 0.4.2 up to 1.3.1 contains a Cross ite Request Forgery (CSRF) vulnerability in Pym.js _onNavigateToMessage function. https://github.com/npr | Mar 13, 2018 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Npr.
Media articles that mention a CVE ID that affects a product developed by Npr — matched by CVE ID, not by vendor name.