repomix vulnerabilities
CVEs whose affected-version data names the repomix package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-49987High· 8.8repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection
repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection
▾ Twilightrepomix · repomixEPSS 0.54%via GHSA
CVE-2026-49988Mediumrepomix: attach_packed_output can bypass file-read secret scanning for supported local files
repomix: attach_packed_output can bypass file-read secret scanning for supported local files
▾ Sunlitrepomix · repomixEPSS 0.20%via GHSA