Answer in brief
CVE-2026-76833 records a High severity (CVSS 7.8) vulnerability in @cgauge/yaml npm Package Arbitrary Code Execution via eval() YAML Tag. The current sources do not mark it as known exploited. The current feed maps cgauge/@cgauge/yaml (generic), cgauge/@cgauge/yaml (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps cgauge/@cgauge/yaml (generic), cgauge/@cgauge/yaml (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| cgauge/@cgauge/yamlgeneric | 0 | Not reported |
| cgauge/@cgauge/yamlgeneric | * | Not reported |
Published upstream
Aug 20, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 20, 2026
@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string values during document parsing. Any application parsing untrusted YAML input with this library exposes full Node.js runtime authority, including environment variable access, filesystem read/write, network access, and subprocess execution, with no safe-mode alternative or opt-out mechanism available.
Quoted source text, attributed separately from HOL analysis.