github.com/OliveTin/OliveTin vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53541Mediumgithub.com/OliveTin/OliveTin: OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input FilteringCVE-2026-48709Lowgithub.com/OliveTin/OliveTin: OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument EnumerationCVE-2026-48708Highgithub.com/OliveTin/OliveTin: OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command ContaminationGHSA-XX6G-43W2-9G6GMediumgithub.com/OliveTin/OliveTin: OliveTin's email argument makes compliance harder, enables log injectionCVE-2026-32102Highgithub.com/OliveTin/OliveTin: OliveTin Vulnerable to Unauthorized Action Output Disclosure via EventStreamCVE-2026-31817Highgithub.com/OliveTin/OliveTin: OliveTin's unsafe parsing of UniqueTrackingId can be used to write filesCVE-2026-30233Mediumgithub.com/OliveTin/OliveTin: OliveTin doesn't check view permission when returning dashboardsGHSA-FWHJ-785H-43HHMediumgithub.com/OliveTin/OliveTin: OliveTin has crash on NPE by calling APIs with invalid bindings or log referencesCVE-2026-30225Mediumgithub.com/OliveTin/OliveTin: OliveTin's RestartAction always runs actions as guestCVE-2026-30224Mediumgithub.com/OliveTin/OliveTin: OliveTin Session Fixation: Logout Fails to Invalidate Server-Side SessionCVE-2026-30223Highgithub.com/OliveTin/OliveTin: OliveTin has JWT Audience Validation Bypass in Local Key and HMAC ModesCVE-2026-28790Highgithub.com/OliveTin/OliveTin: OliveTin has Unauthenticated Action Termination via KillAction When Guests Must LoginCVE-2026-28789Highgithub.com/OliveTin/OliveTin: OliveTin has unauthenticated DoS via concurrent map writes in OAuth2 state handlingCVE-2026-28342Highgithub.com/OliveTin/OliveTin: OliveTin has Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API EndpointCVE-2026-27626Criticalgithub.com/OliveTin/OliveTin: OliveTin: OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell safety checksCVE-2025-50946Highgithub.com/OliveTin/OliveTin: OliveTin OS Command Injection vulnerability

Stop the waste.
Protect your environment with Kodem.