cyberchef
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting cyberchefpage 1 of 1
- CVE-2019-15532MEDIUMCVSS 6.1EG 6.1fixed in 8.31.32019-08-26
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
- CVE-2026-42615HIGHCVSS 7.2EG 7.2fixed in 11.0.02026-04-29
GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.
- CVE-2026-57439MEDIUMCVSS 5.0EG 5.0fixed in 11.2.02026-07-08
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with …
Check whether cyberchef is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for cyberchef CVEs against the assets you own.
Book a Demo →