// disclosure record
CVEs & advisories
Every vulnerability I have reported to a maintainer, with its public identifier where one has been assigned. Rows link to the full writeup: root cause, proof of concept, fix, and timeline. The table is generated from each writeup's metadata, so it stays in step with the research.
- Advisories
- 5
- CVE IDs
- 4
- Patched
- 4
- Years active
- 2026
| Identifier | Affected | Severity | Weakness | Status | Date |
|---|---|---|---|---|---|
| ID pendingdecompress-zip: Zip Slip Arbitrary File Write via a Sibling-Prefix Bypass | Affecteddecompress-zip ≤ 0.3.3 (no fix available)npm · bower/decompress-zip | Severity High 8.1 | WeaknessCWE-22 | Status Public | Date |
| CVE-2026-59972GHSA-2756-j7rr-9464unzipper: Zip Slip Arbitrary File Write via a Sibling-Prefix Path Bypass | Affectedunzipper ≤ 0.12.4npm · ZJONSSON/node-unzipperfixed in 0.12.5 | Severity High 8.1 | WeaknessCWE-22 | Status Patched | Date |
| CVE-2026-55091GHSA-hp36-v28f-w3r4flat-to-nested: Prototype Pollution via a __proto__ Parent Key | Affectedflat-to-nested ≤ 1.1.1npm · joaonuno/flat-to-nested-jsfixed in 1.1.2 | Severity High 7.5 | WeaknessCWE-1321 | Status Patched | Date |
| CVE-2026-54283GHSA-82w8-qh3p-5jfqStarlette: Form-Parser Limits Silently Ignored for URL-Encoded Bodies | Affectedstarlette >= 0.4.1, < 1.3.1PyPI · encode/starlettefixed in 1.3.1 | Severity High 7.5 | WeaknessCWE-770 | Status Patched | Date |
| CVE-2026-63358FileGator v7.14.0: Privilege Escalation via Unvalidated chmod Endpoint | AffectedFileGator < 7.14.2Packagist · filegator/filegatorfixed in 7.14.2 | Severity High 7.3 | WeaknessCWE-732 | Status Patched | Date |
Status vocabulary
- Reported
- Sent to the maintainer; awaiting acknowledgement or fix.
- Coordinated
- Acknowledged; fix and identifier in progress under embargo.
- Patched
- A fixed release is available.
- Public
- Details published; no vendor fix applies (class or research).
Disclosure policy
90-day coordinated disclosure from the date a vendor acknowledges receipt. If a vendor is unresponsive after reasonable follow-up, or active exploitation is observed, I may publish sooner. Full policy.