All 4 CVE vulnerabilities found in repomix, with AI-generated Chinese analysis, references, and POCs.
Vendor: repomix
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-49987 | Repomix: Command Injection (RCE) via `--remote-branch` Argument Injection CWE-88 | - | - | 2026-07-15 |
| CVE-2026-49988 | Repomix: attach_packed_output can bypass file-read secret scanning for supported local files CWE-200 | - | - | 2026-07-15 |
| CVE-2026-59702 | repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack CWE-918 | 9.3 | Critical | 2026-07-08 |
| CVE-2026-59703 | repomix - Local File Inclusion via file:// URL Scheme in Git Clone Endpoint CWE-552 | 7.5 | High | 2026-07-08 |
All 4 known CVE vulnerabilities affecting repomix with full Chinese analysis, references, and POCs where available.