// case studies

Real CVEs. Real code. PullLight caught them.

Thirty-one vulnerabilities across popular npm, Python, PHP, Go, and Java packages — flagged by AI review before they shipped. Ordered by CVSS score.

Browse by bug class →

10.0
CVSS
CVE-2025-53833
Pre-Auth RCE via Unescaped Blade Template Injection
LaRecipe SSTI RCE
LaRecipe
Jul 2025
10.0
CVSS
CVE-2025-55182
RCE via Unvalidated RSC Deserialization
React2Shell RCE
react2shell
Nov 2025
10.0
CVSS
CVE-2026-44005
Prototype Pollution / Sandbox Escape
vm2 Sandbox Escape
vm2
May 2026
9.9
CVSS
CVE-2025-49113
PHP Object Deserialization via _from Parameter
Roundcube Post-Auth RCE
roundcubemail
Jun 2025
9.8
CVSS
CVE-2025-66434
Pre-Auth RCE via Unescaped Jinja2 Template Context
ERPNext Dunning SSTI RCE
Frappe ERPNext
Dec 2025
9.8
CVSS
CVE-2025-31488
RCE via eval() on Unsanitized Auth Metadata
Winston Auth RCE
winston-auth
Apr 2025
9.8
CVSS
CVE-2026-1774
Prototype Pollution → Authorization Bypass
CASL Prototype Pollution
@casl/ability
Feb 2026
9.8
CVSS
CVE-2024-23897
CLI Argument Injection via args4j expandAtFiles()
Jenkins CLI Argument Injection
jenkins
Jan 2024
9.8
CVSS
CVE-2025-24813
Path Equivalence + Unsafe Deserialization in DefaultServlet
Tomcat Partial PUT RCE
tomcat
Mar 2025
9.8
CVSS
CVE-2025-24813
RCE via Partial PUT Path Equivalence
Apache Tomcat Path Equivalence RCE
tomcat
Mar 2025
9.8
CVSS
CVE-2025-11953
OS Command Injection via CLI Package Installation
React Native CLI Command Injection
@react-native-community/cli
Nov 2025
9.8
CVSS
CVE-2026-33352
SQL Injection via Backslash-Escape Bypass
AVideo SQL Injection
WWBN/AVideo
Mar 2026
9.8
CVSS
CVE-2026-5760
Supply-Chain SSTI via Model-Supplied Jinja2 Template in GGUF Reranking
SGLang GGUF SSTI RCE
sglang
Apr 2026
9.3
CVSS
CVE-2024-42005
SQL Injection via Unvalidated Column Aliases
Django JSONField SQL Injection
django
Aug 2024
9.2
CVSS
CVE-2025-68428
Path Traversal via Unsanitized File Write
jsPDF Path Traversal
jspdf
Sep 2025
9.1
CVSS
CVE-2024-49768
TOCTOU Race in HTTP Pipelining
Waitress TOCTOU Race
waitress
Nov 2024
9.1
CVSS
CVE-2025-29927
Auth Bypass via Middleware Logic Gap
Next.js Auth Bypass
next
Mar 2025
9.1
CVSS
CVE-2025-20868
Arbitrary File Read via pct-decoding in claims parsing
golang-jwt/jwt Claims Parsing File Read
golang-jwt/jwt
Jan 2026
9.1
CVSS
CVE-2026-46624
SQL Injection leading to OS Command Execution via timeZone
Twenty CRM SQLi to RCE
twentyhq/twenty
May 2026
9.0
CVSS
CVE-2024-21534
Sandbox Escape via unsafe vm.compile
jsonpath-plus RCE
jsonpath-plus
Oct 2024
8.8
CVSS
CVE-2025-55164
Prototype Pollution via Plain Object CSP Parsing (CWE-1321)
@helmetjs CSP Parser Prototype Pollution
@helmetjs/csp-parser
Aug 2025
8.7
CVSS
CVE-2024-39338
axios SSRF via NO_PROXY Environment Variable Bypass
axios SSRF via NO_PROXY Bypass
axios
Aug 2024
8.6
CVSS
CVE-2026-44578
WebSocket Upgrade Handler SSRF
Next.js WebSocket SSRF
next
May 2026
8.2
CVSS
CVE-2026-22731
Authentication Bypass under Actuator Health Groups Paths
Spring Boot Auth Bypass
spring-boot
Mar 2026
8.1
CVSS
CVE-2024-29415
SSRF via IPv4/IPv6 Canonicalization Bypass
ip Package SSRF Bypass
ip
Apr 2024
Want PullLight watching your PRs?
Catches bugs like these before they merge — no config required.
Try the live demo →