HIGH
cgauge
CVE published 2026-08-20
CVE-2026-76833
The CVE-2026-76833 vulnerability in the @cgauge/yaml npm package allows for arbitrary code execution via a custom !js YAML tag. This issue is significant because it enables attackers to execute arbitrary JavaScript, potentially leading to full Node.js runtime authority compromise. Node.js applications parsing untrusted YAML input with this library are at risk, with potential impacts including environment [truncated]