Xygeni develops software supply-chain security and software composition analysis tools, with observed vulnerabilities centered on its Xygeni Action product and featuring embedded malicious code as the primary weakness class. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xygeni over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31976CRITICAL xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) inject | Mar 11, 2026 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xygeni.
Media articles that mention a CVE ID that affects a product developed by Xygeni — matched by CVE ID, not by vendor name.