morgan vulnerabilities
CVEs whose affected-version data names the morgan package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-15603Medium· 5.3morgan vulnerable to Log Forging via unescaped Unicode line separators
morgan vulnerable to Log Forging via unescaped Unicode line separators
▾ Sunlitmorgan · morganEPSS 0.24%via GHSA
CVE-2026-5078Medium· 5.3morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
▾ Sunlitmorgan · morganEPSS 0.33%via GHSA