Security: mljar/mercury
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Stored / DOM Cross-Site Scripting (XSS): mr.Markdown renders untrusted content as raw, unsanitized HTMLGHSA-2658-85cv-9wwq published
Sep 11, 2026 by pplonskiModerate -
Unauthenticated Remote Code Execution via /api/kernels - anonymous users can start a kernel and execute arbitrary Python (blocklist does not cover kernels; survives the /api/terminals fix)GHSA-rv4m-xm3f-3ccq published
Aug 31, 2026 by pplonskiCritical -
Unauthenticated Remote Code Execution in /api/terminals - access control bypassGHSA-f8c7-rwf9-fmgm published
Aug 21, 2026 by pplonskiCritical
Learn more about advisories related to mljar/mercury in the GitHub Advisory Database