{"schema_version":1,"title":"@keystone-6/core (npm) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in @keystone-6/core (npm): 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-63421, was published on 21 August 2026.","url":"https://junglewise.ai/threats/technologies/keystone-6-core","json_url":"https://junglewise.ai/threats/technologies/keystone-6-core.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/keystone-6-core","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":8,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":3},"latest":[{"cve":"CVE-2026-63421","cvss":7.5,"epss":0.0067,"slug":"cve-2026-63421-keystone-graphql-maxtake-bypass-with-negative-values","title":"Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.t","severity":"high","exploited":false,"published_at":"2026-08-21T21:17:01.643+00:00","url":"https://junglewise.ai/threats/cve-2026-63421-keystone-graphql-maxtake-bypass-with-negative-values"},{"cve":"CVE-2026-10802","cvss":4.3,"epss":0.0031,"slug":"cve-2026-10802-keystonejs-denial-of-service-via-unbounded-graphql-query-depth","title":"KeystoneJS Denial of Service via Unbounded GraphQL Query Depth","severity":"medium","exploited":false,"published_at":"2026-06-04T12:16:24.267+00:00","url":"https://junglewise.ai/threats/cve-2026-10802-keystonejs-denial-of-service-via-unbounded-graphql-query-depth"},{"cve":"CVE-2026-33326","cvss":3.1,"epss":0.0028,"slug":"cve-2026-33326-keystonejs-keystone-6-core-authorization-bypass-in-findmany","title":"KeystoneJS @keystone-6/core authorization bypass in findMany cursor parameter","severity":"low","exploited":false,"published_at":"2026-03-19T18:37:42+00:00","url":"https://junglewise.ai/threats/cve-2026-33326-keystonejs-keystone-6-core-authorization-bypass-in-findmany"},{"cve":"CVE-2025-46720","cvss":3.1,"epss":0.0027,"slug":"cve-2025-46720-keystone-isfilterable-bypass-in-update-and-delete-mutations","title":"Keystone isFilterable bypass in update and delete mutations","severity":"low","exploited":false,"published_at":"2025-05-05T18:51:34+00:00","url":"https://junglewise.ai/threats/cve-2025-46720-keystone-isfilterable-bypass-in-update-and-delete-mutations"},{"cve":"CVE-2023-40027","cvss":3.1,"epss":0.0058,"slug":"cve-2023-40027-keystone-keystone-6-core-unauthorized-adminmeta-graphql-access","title":"Keystone @keystone-6/core unauthorized adminMeta GraphQL access","severity":"low","exploited":false,"published_at":"2023-08-15T20:04:14+00:00","url":"https://junglewise.ai/threats/cve-2023-40027-keystone-keystone-6-core-unauthorized-adminmeta-graphql-access"},{"slug":"keystone-6-insecure-cuid-identifier-dependency-63b02e59","title":"Keystone-6 insecure cuid identifier dependency","severity":"info","exploited":false,"published_at":"2023-06-12T18:37:31+00:00","url":"https://junglewise.ai/threats/keystone-6-insecure-cuid-identifier-dependency-63b02e59"},{"cve":"CVE-2022-39382","cvss":3.1,"slug":"cve-2022-39382-keystonejs-keystone-6-core-incorrect-node-env-inlining-via","title":"KeystoneJS @keystone-6/core incorrect NODE_ENV inlining via esbuild","severity":"low","exploited":false,"published_at":"2022-11-03T18:14:05+00:00","url":"https://junglewise.ai/threats/cve-2022-39382-keystonejs-keystone-6-core-incorrect-node-env-inlining-via"},{"cve":"CVE-2022-39322","cvss":3.1,"epss":0.0115,"slug":"cve-2022-39322-keystone-multiselect-field-access-control-bypass","title":"Keystone multiselect field access-control bypass","severity":"low","exploited":false,"published_at":"2022-10-18T17:12:46+00:00","url":"https://junglewise.ai/threats/cve-2022-39322-keystone-multiselect-field-access-control-bypass"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"flowise (npm)","slug":"flowise","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/flowise"},{"name":"vm2 (npm)","slug":"vm2","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/vm2"},{"name":"@budibase/server (npm)","slug":"budibase-server","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/budibase-server"},{"name":"directus (npm)","slug":"directus","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/directus"},{"name":"nocodb (npm)","slug":"nocodb","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/nocodb"},{"name":"hono (npm)","slug":"hono","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/hono"},{"name":"parse-server (npm)","slug":"parse-server","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/parse-server"},{"name":"dompurify (npm)","slug":"dompurify","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/dompurify"},{"name":"ghost (npm)","slug":"ghost","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/ghost"},{"name":"flowise-components (npm)","slug":"flowise-components","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/flowise-components"},{"name":"astro (npm)","slug":"astro","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/astro"},{"name":"@anthropic-ai/claude-code (npm)","slug":"anthropic-ai-claude-code","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/anthropic-ai-claude-code"}],"technology":{"hub":true,"name":"@keystone-6/core (npm)","slug":"keystone-6-core","vendor":{"name":"npm","slug":"npm","url":"https://junglewise.ai/threats/vendors/npm"},"aliases":[],"homepage":"https://keystonejs.com/","repo_url":"https://github.com/keystonejs/keystone","description":"The core package for Keystone 6, a headless content management system and GraphQL API builder for Node.js.","url":"https://junglewise.ai/threats/technologies/keystone-6-core"},"most_severe":[{"cve":"CVE-2026-63421","cvss":7.5,"epss":0.0067,"slug":"cve-2026-63421-keystone-graphql-maxtake-bypass-with-negative-values","title":"Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.t","severity":"high","exploited":false,"published_at":"2026-08-21T21:17:01.643+00:00","url":"https://junglewise.ai/threats/cve-2026-63421-keystone-graphql-maxtake-bypass-with-negative-values"},{"cve":"CVE-2026-10802","cvss":4.3,"epss":0.0031,"slug":"cve-2026-10802-keystonejs-denial-of-service-via-unbounded-graphql-query-depth","title":"KeystoneJS Denial of Service via Unbounded GraphQL Query Depth","severity":"medium","exploited":false,"published_at":"2026-06-04T12:16:24.267+00:00","url":"https://junglewise.ai/threats/cve-2026-10802-keystonejs-denial-of-service-via-unbounded-graphql-query-depth"},{"cve":"CVE-2022-39322","cvss":3.1,"epss":0.0115,"slug":"cve-2022-39322-keystone-multiselect-field-access-control-bypass","title":"Keystone multiselect field access-control bypass","severity":"low","exploited":false,"published_at":"2022-10-18T17:12:46+00:00","url":"https://junglewise.ai/threats/cve-2022-39322-keystone-multiselect-field-access-control-bypass"},{"cve":"CVE-2023-40027","cvss":3.1,"epss":0.0058,"slug":"cve-2023-40027-keystone-keystone-6-core-unauthorized-adminmeta-graphql-access","title":"Keystone @keystone-6/core unauthorized adminMeta GraphQL access","severity":"low","exploited":false,"published_at":"2023-08-15T20:04:14+00:00","url":"https://junglewise.ai/threats/cve-2023-40027-keystone-keystone-6-core-unauthorized-adminmeta-graphql-access"},{"cve":"CVE-2026-33326","cvss":3.1,"epss":0.0028,"slug":"cve-2026-33326-keystonejs-keystone-6-core-authorization-bypass-in-findmany","title":"KeystoneJS @keystone-6/core authorization bypass in findMany cursor parameter","severity":"low","exploited":false,"published_at":"2026-03-19T18:37:42+00:00","url":"https://junglewise.ai/threats/cve-2026-33326-keystonejs-keystone-6-core-authorization-bypass-in-findmany"},{"cve":"CVE-2025-46720","cvss":3.1,"epss":0.0027,"slug":"cve-2025-46720-keystone-isfilterable-bypass-in-update-and-delete-mutations","title":"Keystone isFilterable bypass in update and delete mutations","severity":"low","exploited":false,"published_at":"2025-05-05T18:51:34+00:00","url":"https://junglewise.ai/threats/cve-2025-46720-keystone-isfilterable-bypass-in-update-and-delete-mutations"},{"cve":"CVE-2022-39382","cvss":3.1,"slug":"cve-2022-39382-keystonejs-keystone-6-core-incorrect-node-env-inlining-via","title":"KeystoneJS @keystone-6/core incorrect NODE_ENV inlining via esbuild","severity":"low","exploited":false,"published_at":"2022-11-03T18:14:05+00:00","url":"https://junglewise.ai/threats/cve-2022-39382-keystonejs-keystone-6-core-incorrect-node-env-inlining-via"},{"slug":"keystone-6-insecure-cuid-identifier-dependency-63b02e59","title":"Keystone-6 insecure cuid identifier dependency","severity":"info","exploited":false,"published_at":"2023-06-12T18:37:31+00:00","url":"https://junglewise.ai/threats/keystone-6-insecure-cuid-identifier-dependency-63b02e59"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}