CVE-2025-14695Medium· 6.3▾ SunlitA vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing manipulati…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing manipulation of the argument action can lead to dynamically-managed code resources. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13659High· 8.8Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code executio…
GHSA-5v7w-95g5-pj6qCritical· 10.0Duplicate Advisory: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
GHSA-gg6f-mhqm-f7gpCritical· 10.0Duplicate Advisory: Sandbox Escape (NodeVM)
GHSA-29x6-9qh5-83ggCritical· 10.0Duplicate Advisory: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCE
CVE-2026-105180Medium· 6.3A vulnerability was determined in Jeebase 0.0.1
GHSA-9fxx-mv6c-j5xpCritical· 9.0Duplicate Advisory: NodeVM nesting guard accepts array-shaped require and permits host RCE