I intend to monitor these vulnerabilities going forward. Should the situation change, I will publish updates.
The following vulnerabilities are covered. For details, please listen to the podcast.
CVE-2026-0939
CVE-2025-14757
CVE-2026-1003
CVE-2026-0913
A security bypass vulnerability in pnpm v10+ allows git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle...
On December 19, 2025, MongoDB disclosed information regarding a vulnerability (CVE-2025-14847) in MongoDB involving information disclosure from uninitialized heap memory. If exploited, an unauthenticated...
Caught a cold