CVE-2026-2265

Publication date

2026-04-01 16:11:25

Family

certcc

State

PUBLISHED

Description

An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.