Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/@keystone-6/core — 5 CVEs · VulnScope
pkg:npm/
@keystone-6/core
5 total CVEs
CRITICAL
2
MEDIUM
2
LOW
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2022-39382
@keystone-6/core's NODE_ENV defaults to development with esbuild
>= 3.0.0, < 3.0.2
CRITICAL
9.1
CVE-2022-39322
Field-level access-control bypass for multiselect field
>= 2.2.0, < 2.3.1
MEDIUM
5.3
CVE-2023-40027
When `ui.isAccessAllowed` is `undefined`, the `adminMeta` GraphQL query is publicly accessible
from 0, < 5.5.1
MEDIUM
4.3
@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany (CVE-2025-46720 incomplete fix)
from 0, < 6.5.2
LOW
3.1
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
from 0, < 6.5.0
CVE-2026-33326
CVE-2025-46720