rsec-2026-0

osv_cran
Description

The widgetframe R package is exposed to a vulnerability due to its use of the Pym.js library version 1.3.1. This can result in arbitrary javascript code execution.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://github.com/RConsortium/r-advisory-database/blob/main/vulns/widgetframe/RSEC-2026-0.yaml"
      },
      "package": {
        "ecosystem": "CRAN",
        "name": "widgetframe",
        "purl": "pkg:cran/widgetframe"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.1.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "0.1.0",
        "0.2.0",
        "0.3.0",
        "0.3.1"
      ]
    }
  ],
  "details": "The widgetframe R package is exposed to a vulnerability due to its use of the Pym.js library version 1.3.1.  This can result in arbitrary javascript code execution.",
  "id": "RSEC-2026-0",
  "modified": "2026-02-18T22:30:36.922343Z",
  "published": "2026-02-18T10:30:00Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000086"
    },
    {
      "type": "WEB",
      "url": "https://blog.apps.npr.org/2018/02/15/pym-security-vulnerability.html"
    },
    {
      "type": "WEB",
      "url": "https://github.com/trafficonese/widgetframe/issues/12"
    },
    {
      "type": "WEB",
      "url": "https://github.com/trafficonese/widgetframe/pull/13"
    }
  ],
  "schema_version": "1.7.3",
  "summary": "Cross-site Request Forgery (CSRF) vulnerability",
  "upstream": [
    "CVE-2018-1000086"
  ]
}
View JSON API Download JSON