Security: encoredev/encore
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
-
Code injection via adversarial doc comments for `encore gen client`GHSA-jm2f-2pwf-qfv9 published
Jul 29, 2026 by eandreLow -
Path traversal in the local object storage emulatorGHSA-5cq5-fpx7-2wmx published
Jul 29, 2026 by eandreModerate -
Encore CLI daemon exposes localhost-bound development servers to cross-origin browser requestsGHSA-wpvj-6m4r-5v3h published
Jul 29, 2026 by eandreCritical -
Decimal DoSGHSA-72fg-v7vh-4q32 published
Jul 29, 2026 by eandreModerate -
CLI cross-origin WebSocketGHSA-8wqj-wmx4-3j23 published
Jul 29, 2026 by eandreHigh -
Spoofed internal metadata headers accepted by the API gatewayGHSA-j97h-57vg-4vcc published
Jul 29, 2026 by eandreCritical
Learn more about advisories related to encoredev/encore in the GitHub Advisory Database