{"affected":[{"database_specific":{"source":"https://github.com/RConsortium/r-advisory-database/blob/main/vulns/widgetframe/RSEC-2026-0.yaml"},"package":{"ecosystem":"CRAN","name":"widgetframe","purl":"pkg:cran/widgetframe"},"ranges":[{"events":[{"introduced":"0.1.0"}],"type":"ECOSYSTEM"}],"versions":["0.1.0","0.2.0","0.3.0","0.3.1"]}],"details":"The widgetframe R package is exposed to a vulnerability due to its use of the Pym.js library version 1.3.1.  This can result in arbitrary javascript code execution.","id":"RSEC-2026-0","modified":"2026-02-18T22:30:36.922343Z","published":"2026-02-18T10:30:00Z","references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000086"},{"type":"WEB","url":"https://blog.apps.npr.org/2018/02/15/pym-security-vulnerability.html"},{"type":"WEB","url":"https://github.com/trafficonese/widgetframe/issues/12"},{"type":"WEB","url":"https://github.com/trafficonese/widgetframe/pull/13"}],"schema_version":"1.7.3","summary":"Cross-site Request Forgery (CSRF) vulnerability","upstream":["CVE-2018-1000086"]}