{"api_version":"v1","generated_at":"2026-10-07T17:05:00+00:00","product":{"cve_count":8,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-keystonejs-keystone-52a3ee2687fd","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/keystone","name":"keystone","next_cursor":null,"observations":[{"affected":"< 6.5.3","affected_versions_present":true,"cve_id":"CVE-2026-63421","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63421","fixed":"6.5.3.","last_modified":"2026-08-26T17:39:12.659Z","patch_url":"https://github.com/keystonejs/keystone/security/advisories/GHSA-cqmq-8755-7xvh","primary_source":"","published":"2026-08-21T20:15:16.459Z"},{"affected":"20260319","affected_versions_present":true,"cve_id":"CVE-2026-10802","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-10802","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-04T12:31:20.535Z","patch_url":"","primary_source":"","published":"2026-06-04T11:15:10.397Z"},{"affected":"< 6.5.2","affected_versions_present":true,"cve_id":"CVE-2026-33326","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33326","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-25T13:37:10.313Z","patch_url":"","primary_source":"","published":"2026-03-24T19:08:05.877Z"},{"affected":"< 6.5.0","affected_versions_present":true,"cve_id":"CVE-2025-46720","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-46720","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-05T19:00:01.531Z","patch_url":"https://github.com/keystonejs/keystone/security/advisories/GHSA-hg9m-67mm-7pg3","primary_source":"","published":"2025-05-05T18:53:51.506Z"},{"affected":"< 5.5.1","affected_versions_present":true,"cve_id":"CVE-2023-40027","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-40027","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-10-02T17:45:51.611Z","patch_url":"https://github.com/keystonejs/keystone/security/advisories/GHSA-9cvc-v7wm-992c","primary_source":"","published":"2023-08-15T17:45:54.439Z"},{"affected":"<= 7.0.0","affected_versions_present":true,"cve_id":"CVE-2023-34247","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-34247","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-01-03T18:07:02.632Z","patch_url":"https://github.com/keystonejs/keystone/pull/8626","primary_source":"","published":"2023-06-13T16:31:31.545Z"},{"affected":">= 3.0.0, < 3.0.2","affected_versions_present":true,"cve_id":"CVE-2022-39382","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-39382","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-22T16:08:20.892Z","patch_url":"https://github.com/keystonejs/keystone/pull/8031/","primary_source":"","published":"2022-11-03T00:00:00.000Z"},{"affected":">= 2.2.0, < 2.3.1","affected_versions_present":true,"cve_id":"CVE-2022-39322","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-39322","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-22T17:17:35.770Z","patch_url":"https://github.com/keystonejs/keystone/commit/65c6ee3deef23605fc72b80230908696a7a65e7c","primary_source":"","published":"2022-10-25T00:00:00.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"keystonejs"}}
