rsshub
npm6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting rsshubpage 1 of 1
- CVE-2021-21278HIGHCVSS 8.6EG 8.62021-01-26
RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected…
- CVE-2022-31110MEDIUMCVSS 5.3EG 5.32022-06-29
RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to the `filter` and `filterout` parameters can cause an abnormally high CPU. This results in an impact on the performance…
- CVE-2023-22493HIGHCVSS 8.8EG 8.8✓ Fixed in 1.0.0-master.a66cbcf2023-01-13
RSSHub is an open source RSS feed generator. RSSHub is vulnerable to Server-Side Request Forgery (SSRF) attacks. This vulnerability allows an attacker to send arbitrary HTTP requests from the server to other servers or resources on the net…
- CVE-2023-26491MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.0.0-master.c910c4d2023-03-03
RSSHub is an open source and extensible RSS feed generator. When the URL parameters contain certain special characters, it returns an error page that does not properly handle XSS vulnerabilities, allowing for the execution of arbitrary Jav…
- CVE-2024-27926MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.0.0-master.d8ca9152024-03-21
RSSHub is an open source RSS feed generator. Starting in version 1.0.0-master.cbbd829 and prior to version 1.0.0-master.d8ca915, ahen the specially crafted image is supplied to the internal media proxy, it proxies the image without handlin…
- CVE-2024-27927MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.0.0-master.a4294722024-03-21
RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and retrieve information in the internal network…
Check whether rsshub is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for rsshub CVEs against the assets you own.
Start Free Scan →