eta
155 known vulnerabilities · 2 critical · 2 high
Eta vulnerable to Code Injection via templates rendered with user-defined data
Malicious code in @accordproject/concerto-metamodel (npm)
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists
OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow paths
nanotar is vulnerable to path traversal in parseTar() and parseTarGzip()
Malicious code in azure-arm-resourcegraph-samples-js-beta (npm)
Malicious code in azure-arm-servicemap-samples-js-beta (npm)
Malicious code in azure-arm-dnsresolver-samples-js-beta (npm)
Malicious code in azure-arm-dnsresolver-samples-ts-beta (npm)
Malicious code in azure-arm-machinelearningexperimentation-samples-js-beta (npm)
Malicious code in azure-arm-machinelearningexperimentation-samples-ts-beta (npm)
Malicious code in azure-arm-oep-samples-js-beta (npm)
OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback)
Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization
OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy
Malicious code in colors-beta (npm)
OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata
Malicious code in metadata-api-nodejs (npm)
Malicious code in azure-arm-servicefabricmesh-samples-js-beta (npm)
Malicious code in azure-arm-labservices-samples-js-beta (npm)
Malicious code in azure-arm-servicefabricmesh-samples-ts-beta (npm)
Malicious code in azure-arm-resourcegraph-samples-ts-beta (npm)
Malicious code in azure-arm-visualstudio-samples-js-beta (npm)
Malicious code in is-meta (npm)
OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction
Malicious code in meta-horizon (npm)
Malicious code in meta-horizon-remake (npm)
OpenClaw has agent avatar symlink traversal in gateway session metadata
Malicious code in @ncr-swt-retail/scox-npm-group (npm)
Malicious code in metalmi (npm)
Malicious code in metamask-docs (npm)
When `ui.isAccessAllowed` is `undefined`, the `adminMeta` GraphQL query is publicly accessible
OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
Malicious code in careers-job-detail (npm)
@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details
Malicious code in @sme-ui/aoma-vevasound-metadata-lib (npm)
Malicious code in updated-script-retail-tycoon-2-script-h-a-c-k-9u9pw3 (npm)
Malicious code in ngpd-merceros-ui-meta (npm)
Malicious code in metamask-sdk-monorepo (npm)
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
Malicious code in azure-arm-labservices-samples-ts-beta (npm)
Malicious code in azure-arm-netapp-samples (npm)
parse-server: Malformed `$regex` query leaks database error details in API response
Malicious code in @f5rest/odata-v4-service-metadata (npm)
Malicious code in azure-arm-servicemap-samples-ts-beta (npm)
Malicious code in metadata-collector (npm)
Malicious code in theta-tv-charts (npm)
Duplicate Advisory: OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata
OpenClaw: Bonjour/DNS-SD TXT metadata steers CLI routing after failed service resolution
OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reachable)
@backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch
Duplicate Advisory: OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback)
Malicious code in azure-template-samples-ts-beta (npm)
Malicious code in importlib-metadata (npm)
Malicious code in @tekion/beta (npm)
Malicious code in com.meta.xrpa (npm)
node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization
Malicious code in metadata-attacher (npm)
Malicious code in com.meta.quest.sdk.empty (npm)
Malicious code in contract-metadata (npm)
Malicious code in dc-comments-beta-dropin (npm)
Malicious code in @ramp106/timetable (npm)
Malicious code in src_components_ibtdetail_index_tsx (npm)
Malicious code in meta-ai-client (npm)
Malicious code in com.meta.xr.sdk.avatars.sample.assets (npm)
Malicious code in @reserach_org_jfhalsdhfkslsfds/metadata-collector (npm)
Malicious code in package-meta-resolver (npm)
Malicious code in discord.js-beta (npm)
Duplicate Advisory: OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Unhead Vulnerable to Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity
Malicious code in noblox.js-beta (npm)
metascraper before v5.2.0 vulnerable to stored cross-site scripting
Malicious code in scm-retail-ui (npm)
Malicious code in jpeg-metadata (npm)
Malicious code in azure-arm-containerregistry-samples-ts-beta (npm)
Malicious code in com.meta.xr.sdk.empty (npm)
Malicious code in @ncr-swt-retail/scox-npm-releases (npm)
Malicious code in metadata-lib (npm)
Malicious code in lead-marketing-metadata (npm)
Malicious code in @metadata-ipfs/bonk.fun-ipfs (npm)
jsPDF Vulnerable to Stored XMP Metadata Injection (Spoofing & Integrity Violation)
Malicious code in metaplex (npm)
Malicious code in @apiary-annex/meta (npm)
Malicious code in dvpawebwidgetsdetailspageclient (npm)
Malicious code in azure-arm-containerregistry-samples-js-beta (npm)
Malicious code in azure-arm-mobilenetwork-samples-js-beta (npm)
Malicious code in azure-arm-netapp-samples-ts (npm)
Malicious code in azure-dtdl-parser-samples-js-beta (npm)
Malicious code in upstartautoretailadmin (npm)
Malicious code in @ifings/metatron3 (npm)
Malicious code in invoicetax-paypal (npm)
Malicious code in chai-beta (npm)
Malicious code in detailimg (npm)
Malicious code in load-image-meta (npm)
Malicious code in meta-titik (npm)
Malicious code in ttf-metadata (npm)
Malicious code in fc-personal-details (npm)
Malicious code in metalsapi-adapter (npm)
Malicious code in meta-left-pad (npm)
Malicious code in metamask (npm)
Malicious code in metamask-state-log-explorer (npm)
Malicious code in heflectmetadata (npm)
Malicious code in metaflow-ui (npm)
Malicious code in shipmentdetails-paypal (npm)
Malicious code in olrfdwpetayuknqb (npm)
Malicious code in devcenter-internal-beta (npm)
Malicious code in beta-fhr (npm)
Malicious code in beta-fhr-nxt (npm)
Malicious code in sc-meta-layer (npm)
Malicious code in ens-metadata-service (npm)
Possible prototype pollution in metadata record, when using meta decorator
Malicious code in metabase-enterprise (npm)
Malicious code in metamask-sdk-create-react-app (npm)
Malicious code in metamask-design-tokens-tailwind (npm)
Malicious code in adobetagmanager (npm)
Malicious code in next-sweetalert2 (npm)
Malicious code in com.unity.test.metadata-manager (npm)
Malicious code in ac-sasskit-beta (npm)
Malicious code in @solmasterv3/solana-metadata-sdk (npm)
Malicious code in retail-common (npm)
Malicious code in setan (npm)
Malicious code in retact-vrtualiied (npm)
Malicious code in eth-cmeta (npm)
Malicious code in metacord (npm)
Malicious code in metamodel-editor (npm)
Malicious code in cargo_metadata (npm)
Malicious code in old-mpl-token-metadata (npm)
OpenClaw: macOS beta onboarding exposed PKCE verifier via OAuth state
OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretation
Malicious code in meta-code-verify (npm)
Malicious code in @ensdomains/cypress-metamask (npm)
Malicious code in esbuild-plugin-eta (npm)
Malicious code in metadata-stripper (npm)
Malicious code in beta1 (npm)
Malicious code in ethmetadata (npm)
Malicious code in @pumpfun-sdk/metadata (npm)
Malicious code in @pumpswap-sdk4/metadata (npm)
Malicious code in meta-internal-logger-drzak (npm)
Malicious code in cat-retail-app (npm)
Malicious code in @f5rest/odata-v4-metadata (npm)
Malicious code in @metaplex-foundations/umi-public-keys (npm)
Malicious code in mpl-token-metadata (npm)
Malicious code in com.meta.xr.sdk.avatars (npm)
Malicious code in @f5rest/icr-metadata-generator (npm)
Malicious code in @sasmeee/wabetainfo (npm)
Malicious code in npm_cimetadata (npm)