Octokit is a client library and toolkit for interacting with the GitHub API, with a narrow product scope centered on the core library, associated applications, and webhook handling functionality. The observed vulnerability signal reflects challenges in managing edge cases and exceptional conditions within API client implementations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Octokit over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50728HIGH octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3, 10.9.2, 11.1.2, and 12.0.4, there is a problem caused by an issue with erro | Dec 15, 2023 | 7.5 | 19 | NO | NO |
Octokit is a Ruby toolkit for the GitHub API. Versions 4.23.0 and 4.24.0 of the octokit gem were published containing world-writeable files. Specifically, the gem was packed with f | Jun 15, 2022 | 3.3 | 12 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Octokit.
Media articles that mention a CVE ID that affects a product developed by Octokit — matched by CVE ID, not by vendor name.