← Back to CVE search

CVE-2026-2265

Replicator

Description

An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.

CVSS 6.5EPSS 0.368%Risk 0.67
View source
Published
2026-04-01 17:28:38
Affected versions
<=1.0.5
Type
Package
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N