CWE-914
CVEs classified under CWE-914, newest first.
2 CVEsRSS
CVE-2026-73622High· 7.5gitpython: GitPython: Information disclosure via environment variable expansion in URL handling (CVE-2026-73622)
A flaw was found in GitPython. This vulnerability allows a remote attacker to exfiltrate sensitive information, such as environment variables, by crafting malicious URLs. When these URLs are processed during Git operations like fetch or pu…
▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.35%via CSAF
CVE-2026-44006Critical· 10.0vm2 is an open source vm/sandbox for Node.js
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.
▾ Midnightvm2_project · vm2EPSS 0.81%via NVD