npm package intelligence
@janhq/core Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the npm package @janhq/core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 2
- Known exploited vulnerabilities affecting @janhq/core
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- @janhq/core KEVs with sensor-observed exploitation activity
Review @janhq/core exploitation against the versions you run
Two of the two exploited @janhq/core vulnerabilities tracked here are not in CISA KEV.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
Attested @janhq/core vulnerabilities
2 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2024-36857
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface. |
Beyond CISA | 16 Feb 2026 |
|
CVE-2024-36858
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via... |
Beyond CISA | 16 Feb 2026 |
Recurring weakness patterns
Path Traversal: 'dir\..\..\filename' and Unrestricted Upload of File with Dangerous Type account for mapped occurrences across this @janhq/core KEV portfolio.