@vendure/core
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @vendure/corepage 1 of 1
- CVE-2026-25050MEDIUMCVSS 5.3EG 5.3fixed in 3.5.32026-01-30
Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenticate()` method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses). I…
- CVE-2026-40887CRITICALCVSS 9.1EG 9.1fixed in 3.5.7, 3.6.2 or 2.3.4, by version range2026-04-21
Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string pa…
- CVE-2026-63460HIGHCVSS 7.5EG 7.5fixed in 3.6.52026-09-17
Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service/h…
- CVE-2026-63461MEDIUMCVSS 5.3EG 5.3fixed in 3.6.52026-09-17
Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory visibility guards with caller-supplied filters using the caller-controlled filterOperator…
- CVE-2026-63472CRITICALCVSS 9.1EG 9.1fixed in 3.7.02026-09-17
Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing c…
Check whether @vendure/core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @vendure/core CVEs against the assets you own.
Book a Demo →