monorepo vulnerabilities
CVEs whose affected-version data names the monorepo package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54594Medium· 5.3PoCOmniBlocks is a monorepo for the OmniBlocks project
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenev…
▾ TwilightOmniBlocks · monorepoEPSS 0.33%via NVD
CVE-2026-59262Medium· 6.5PoCAFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines
AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines. Attackers can supply arbitrary document GUID…
▾ Twilightaffine · monorepoEPSS 0.30%via NVD