You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Four new CVE rules, all surfaced by the new npm run intel daily gap check: vitest < 4.1.0 UI-server RCE (CVE-2026-47429), @vitest/browser otelCarrier XSS (CVE-2026-47428), liquidjs < 10.26.0 RCE (CVE-2026-45618), tinymce XSS cluster (CVE-2026-47759/60/61/62)
Proves the intel -> rule -> gate -> release pipeline end to end; VG1076 already flags a real vulnerable pin (vitest 4.0.8) in a production codebase