npm package intelligence

@janhq/core Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the npm package @janhq/core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
2
Known exploited vulnerabilities affecting @janhq/core
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
2
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
@janhq/core KEVs with sensor-observed exploitation activity

Review @janhq/core exploitation against the versions you run

Two of the two exploited @janhq/core vulnerabilities tracked here are not in CISA KEV.

0%
Covered by CISA
100%
Beyond CISA

Attested @janhq/core vulnerabilities

2 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2024-36857

Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.

Beyond CISA 16 Feb 2026
CVE-2024-36858

An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via...

Beyond CISA 16 Feb 2026

Recurring weakness patterns

Path Traversal: 'dir\..\..\filename' and Unrestricted Upload of File with Dangerous Type account for mapped occurrences across this @janhq/core KEV portfolio.

Browse all KEVs →