← volver
CVE-2026-26974

Sylde has Improper Control of Generation of Code

CVSS 7.6 HIGHEPSS 0.5%CWE-829
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.6EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
20 feb 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically imports **/*.plugin.{js,mjs} files including those from node_modules, so any malicious package with a .plugin.js file can execute arbitrary code when installed or required. All projects using this loading behavior are affected, especially those installing untrusted packages. This issue has been fixed in version 0.0.5. To workaround this issue, users can audit and restrict which packages are installed in node_modules.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
Tygo-van-den-Hurk · Slyde

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →