MEDIUM
omnivore-app
CVE published 2026-08-20
CVE-2026-77066
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T11:16:22.100Z and has not been modified since then. The NVD entry is currently 5.3 MEDIUM. The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. An authenticated user can [truncated]