Security advisories

Vulnerabilities we have found in open source packages, and what to do about them

We audit open source packages as part of our development and site audit work. Where we find a vulnerability, we report it to the project, or to MITRE where a project has no security contact, and publish an advisory here once an identifier has been assigned.

Each advisory names the affected function, the class of weakness and the fix. We do not publish exploit code. If you maintain one of these projects, or you coordinate vulnerability records, we will share the verification detail on request: security@graith.co.uk.

Published advisories

CVEPackageAffectedWeaknessSeverity
CVE-2026-95096node-tesseract0.2.7CWE-78High
CVE-2026-95097simple-thumbnail1.6.5CWE-78High
CVE-2026-95098pdf2image1.2.3CWE-78High
CVE-2026-95099notify-send0.1.2CWE-78High
CVE-2026-95100random-token0.0.8CWE-338Medium

Reporting something to us. If you believe you have found a vulnerability in a site or system we maintain, email security@graith.co.uk. We will acknowledge within three working days.

Method

These findings came out of AI-assisted review, using Claude, followed by local verification against the published package. Nothing is reported on the strength of a model's reading alone: each one was reproduced before it was filed, and findings that did not reproduce were dropped.