Skip to main content
// menu
×
>
Loading…
// threat_lookup
×
☰
INTELLIGENCE ROOM
// cybersoc_platform
Dashboard
CVE/RCE
APT
News
Reports
Pulse
SOON
Graph
SOON
Market
SOON
Playback
SOON
NOMINAL
0
Sign in
Join →
CVE-2026-24910 — In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github). — CVE Database · The Intelligence Room