FAIL › dossier
adaltas
VENDORDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 1
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-05-03 | CVE-2021-28860 | critical | In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at ri |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
CISA KEV inclusion indicates critical severity and active exploitation, though vendor response details are absent in provided sources.
neutral
"CVE-2021-28860: In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions."
neutral
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
severe-fallout
"Active Exploitation Alert: Critical CVE-2026-20896 Authentication Bypass in Gitea Docker Image Exposes Repositories and Secrets"
severe-fallout
"Security researchers are warning organizations using Gitea act_runner with the Docker backend to review their deployments after proof-of-concept (PoC) code for CVE-2026-58053 was publicly released"
severe-fallout
"U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog"