StatewardStateward
PlatformPricingComplianceVulnerabilitiesCase studiesDocsBlogAbout
enfr
Book a Demo / ContactGet started free
← All vulnerabilities
MEDIUMSupply chain

GHSA-vvr5-6j6h-rq49

npm · @t-in-one/add_application_tid

Summary

Malicious code in @t-in-one/add_application_tid (npm)

References

  • https://safedep.io/oob-moika-tech-dependency-confusion-campaign/
  • https://github.com/advisories/GHSA-vvr5-6j6h-rq49
SourceStateward
Severitymedium
Also known asMAL-2026-5036
Added2026-05-29

Is your project exposed to this? Stateward checks every dependency on every pull request, and flags it only if your code actually reaches it.

Check my repo
Summarize with
ChatGPTClaudePerplexity

Related vulnerabilities

All Supply chain →
  • HIGHCVE-2026-52801

    Gogs has the ability to import local repositories via Mirror Settings

  • HIGHCVE-2026-52800

    Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

  • HIGHCVE-2026-52799

    Gogs Missing Authorization in Attachment Download

  • HIGHCVE-2026-52798

    Gogs has Stored XSS in `.ipynb` Preview

  • MEDIUMCVE-2026-50179

    @actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

  • HIGHCVE-2026-54353

    @budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

StatewardStateward

Autonomous cybersecurity for your entire codebase.

A venture of Yggdrasil Digital.

Product

  • Platform
  • What we detect
  • How we protect you
  • Pricing
  • Compliance
  • Vulnerabilities
  • Blog
  • Get started free

Resources

  • Breach breakdowns
  • Merge-induced flaws
  • Docs
  • Sample finding
  • Glossary
  • Compare
  • Threat feed API ↗

Company

  • About
  • Yggdrasil Digital ↗

Legal

  • Legal notice
  • Terms of Use
  • Terms of Sale
  • Privacy
  • Cookies
  • DPA

Connect

  • GitHub ↗
  • X ↗
  • Yggdrasil Digital ↗
  • Threat feed (RSS) ↗
  • hello@stateward.com

Stateward provides automated security analysis and does not guarantee detection of all vulnerabilities. It is designed to support, not replace, sound security practices and human judgement.

© 2026 Stateward. All rights reserved.A Yggdrasil Digital venture