Tasks
Every CVE in the bench. 49 tasks · 5 ecosystems · 45 CWE classes · 6 public, the rest a held-out test set (results shown, identity withheld).
49 / 49 tasks
- CVE-2026-30914
Path traversal via backslash normalization discrepancy across FTP/SFTP handlers and VFS backends allows directory escape.
highCWE-22 - CVE-2026-33557
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
criticalCWE-1285 - CVE-2026-41690
Port of i18next-http-middleware CVE-2026-41690 prototype-pollution-via-dotted-segment into mashpie/i18n-node. The i18n-node library already hosts an analogous dotted-key traversal in localeMutator / localeAccessor (i18n.js): `singular.split(objectNotation).reduce((object, index) => ... object[index] = value, locales[locale])`. The vulnerable port weakens the per-segment existence check from Object.prototype.hasOwnProperty.call to a plain `object[index] === undefined`, matching the shape of i18next-http-middleware's pre-3.9.3 setPath. Attacker-controlled dotted keys reaching the public `__` / `__n` API then walk through inherited Object members and write to the shared prototype — leading (`__proto__.polluted`), non-leading (`foo.__proto__.x` — the v3.9.7-style follow-up bypass), and deeper constructor.prototype chains all reach Object.prototype. Fix re-introduces the segment guard at every position via a small lib/safe-set.js helper referenced from both traversal functions.
highCWE-1321 - CVE-2026-25660
Authentication bypass in CodeChecker permission system grants unauthenticated users full access when authentication is enabled.
criticalCWE-863 - CVE-2026-6357
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
highCWE-829 - CVE-2026-31812
quinn-proto transport parameter parsing panics on truncated varints via bare .unwrap() calls, enabling unauthenticated remote DoS with a single UDP packet.
highCWE-248 - 1212bd[private]
details redacted — score and metadata only
highCWE-400 · CWE-770 - e1a260[private]
details redacted — score and metadata only
highCWE-1321 - 9b1e25[private]
details redacted — score and metadata only
mediumCWE-601 - 9a1c46[private]
details redacted — score and metadata only
highCWE-1188 - 5c982a[private]
details redacted — score and metadata only
criticalCWE-915 - 8bb233[private]
details redacted — score and metadata only
highCWE-346 · CWE-350 - 407562[private]
details redacted — score and metadata only
mediumCWE-312 · CWE-313 - 57b3ea[private]
details redacted — score and metadata only
mediumCWE-908 - 7480a4[private]
details redacted — score and metadata only
mediumCWE-639 - e16a3c[private]
details redacted — score and metadata only
highCWE-918 · CWE-863 - a0816b[private]
details redacted — score and metadata only
highCWE-672 - 34c7ae[private]
details redacted — score and metadata only
highCWE-22 - 5c6059[private]
details redacted — score and metadata only
highCWE-35 · CWE-436 - 02cf51[private]
details redacted — score and metadata only
highCWE-770 · CWE-789 - a6d7e7[private]
details redacted — score and metadata only
highCWE-1287 - f7a156[private]
details redacted — score and metadata only
mediumCWE-552 - dd3225[private]
details redacted — score and metadata only
mediumCWE-440 · CWE-697 - 479d6f[private]
details redacted — score and metadata only
highCWE-202 - a29f02[private]
details redacted — score and metadata only
highCWE-22 - 838bae[private]
details redacted — score and metadata only
highCWE-89 · CWE-22 - c11378[private]
details redacted — score and metadata only
highCWE-1321 - bb069f[private]
details redacted — score and metadata only
mediumCWE-1220 - db5e2c[private]
details redacted — score and metadata only
lowCWE-89 - f98add[private]
details redacted — score and metadata only
criticalCWE-22 - 850bd0[private]
details redacted — score and metadata only
highCWE-345 · CWE-494 - 1caece[private]
details redacted — score and metadata only
mediumCWE-284 - f86799[private]
details redacted — score and metadata only
highCWE-22 - b436c4[private]
details redacted — score and metadata only
highCWE-674 - 1a6e93[private]
details redacted — score and metadata only
highCWE-613 · CWE-755 - ed9033[private]
details redacted — score and metadata only
highCWE-863 · CWE-288 - 2cba81[private]
details redacted — score and metadata only
mediumCWE-79 · CWE-183 - 7fb58a[private]
details redacted — score and metadata only
criticalCWE-1392 - 1d2e1a[private]
details redacted — score and metadata only
highCWE-1333 - b9f35e[private]
details redacted — score and metadata only
criticalCWE-668 - 66c024[private]
details redacted — score and metadata only
highCWE-191 · CWE-770 - 3f53bd[private]
details redacted — score and metadata only
highCWE-842 - 8653e4[private]
details redacted — score and metadata only
highCWE-89 - 8e5fa2[private]
details redacted — score and metadata only
highCWE-918 - 0388d3[private]
details redacted — score and metadata only
mediumCWE-639 - d3c3a1[private]
details redacted — score and metadata only
highCWE-347 - d02926[private]
details redacted — score and metadata only
mediumCWE-653 · CWE-863 - 0db863[private]
details redacted — score and metadata only
highCWE-346 · CWE-350 - 5f76f1[private]
details redacted — score and metadata only
highCWE-22