CVE-2026-76833
A permanent, source-backed tracker page. Values are shown only when returned; explicit gaps and read failures remain different states.
What it is
Reported@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string values during document parsing. Any application parsing untrusted YAML input with this library exposes full Node.js runtime authority, including environment variable access, filesystem read/write, network access, and subprocess execution, with no safe-mode alternative or opt-out mechanism available. Source description excerpt; complete tracked detail loads below.
Source reported · Source: CVE record · Source last published: · Source last updated: · Tracker data as of:
What is affected
Reportedcgauge — @cgauge/yaml. Product-level identification only; no affected-version conclusion is available from this field.
Source reported · Source: CVE record · Source last published: · Source last updated: · Tracker data as of:
Urgency and basis
ReportedTrack* · 225.1
Tracker computed · Tracker decision tier from the evidence detailed below · Source last updated: · Tracker data as of:
Exploitation evidence
Not reportedNot reported by tracked sources.
What to do
Not reportedNot reported by tracked sources.
Evidence detail
Loading the full tracker evidence record…