CVE-2026-2265: Replicator
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.
Affected products
- Replicator Replicator: version 1.0.5 only
Published 2026-04-01. Last modified 2026-06-17.