gatsbyjs has 3 CVEs on record between 2022 and 2023. The median CVSS is 8.1 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- gatsby-plugin-mdx 1
- gatsby-plugin-sharp 1
- gatsby-transformer-remark 1
Worst active — by depth score
CVE-2023-22491High· 8.1Gatsby is a free and open source framework based on React that helps developers build websites and apps45CVE-2022-25863High· 8.1The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input…45CVE-2023-30548Medium· 4.3gatsby-plugin-sharp is a plugin for the gatsby framework which exposes functions built on the Sharp image processing library24
gatsbyjs vulnerabilities
CVEs affecting gatsbyjs, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2023-30548Medium· 4.3gatsby-plugin-sharp is a plugin for the gatsby framework which exposes functions built on the Sharp image processing library
gatsby-plugin-sharp is a plugin for the gatsby framework which exposes functions built on the Sharp image processing library. The gatsby-plugin-sharp plugin prior to versions 5.8.1 and 4.25.1 contains a path traversal vulnerability expos…
CVE-2023-22491High· 8.1Gatsby is a free and open source framework based on React that helps developers build websites and apps
Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which…
CVE-2022-25863High· 8.1The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input…
The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input…