SSRF in @asymmetric-effort/specifyjs (CVE-2026-50288). Risk of unauthorized operations or information disclosure. Exploitable via ``assertSecureUrl``. Mitigation: upgrade to `0.2.136` or later.
OS command injection in github.com/coder/coder/v2 (CVE-2026-44454). Confidential information can be exposed externally. Exploitable via ``dotfiles``. Mitigation: upgrade to `2.30.2` or later.