๐Ÿ” CVE Alert

CVE-2026-94038

HIGH 7.3

NonceGeek dim-sum-app Deno Backend main.tsx textSearchV2Handler server-side request forgery

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the argument supabase_url leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 8389032e5d52c28c4855c6126ca7d0eae8af346a. It is best practice to apply a patch to resolve this issue.

CWE CWE-918
Vendor noncegeek
Product dim-sum-app
Published Sep 20, 2026
Stay Ahead of the Next One

Get instant alerts for noncegeek dim-sum-app

Be the first to know when new high vulnerabilities affecting noncegeek dim-sum-app are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

NonceGeek / dim-sum-app
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/407967 vuldb.com: https://vuldb.com/vuln/407967/cti vuldb.com: https://vuldb.com/cve/CVE-2026-94038 vuldb.com: https://vuldb.com/submit/947732 github.com: https://github.com/NonceGeek/dim-sum-app/issues/366 github.com: https://github.com/NonceGeek/dim-sum-app/pull/367 github.com: https://github.com/NonceGeek/dim-sum-app/commit/8389032e5d52c28c4855c6126ca7d0eae8af346a github.com: https://github.com/NonceGeek/dim-sum-app/

Credits

๐Ÿ” dkhonker (VulDB User)