CRITICALnpm
GHSA-fm8p-53ww-hf6w· CVE-2026-61742DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
Modified: 9/24/2026
package
pkg:npm/%40bytebase/dbhub
DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
Modified: 9/24/2026
@bytebase/dbhub's read-only mode does not prevent database writes
Modified: 9/24/2026