IndexedVerified
Config/YAML Security
Generic, YAML, shell, Dockerfile, and CI configuration SAST rules aggregated across verified providers.
Fetch pack
greprules pack fetch config-security --engine opengrepcurl https://api.greprules.io/api/packs/config-security.tar.gz -o config-security.tar.gzIncluded rules
CVE-2026-82862: Model Skill Md Cwe 000 Cve 2026 82862
cve-2026-82862-model-skill-md-cwe-000-cve-2026-82862CVE-2026-82649: Nsis Uncontrolled Search Path Execcve-2026-82649-nsis-uncontrolled-search-path-execCVE-2026-82021: Mcp Manifest Unpinned Git Refcve-2026-82021-mcp-manifest-unpinned-git-refCVE-2026-81753: Flowintel Markdownit Fence Mermaid Xsscve-2026-81753-flowintel-markdownit-fence-mermaid-xssCVE-2026-81731: Frappe Doctype Ignore Xss Filtercve-2026-81731-frappe-doctype-ignore-xss-filterCVE-2026-78391: Jinja Inline Event Handler Xsscve-2026-78391-jinja-inline-event-handler-xssCVE-2026-78122: Docker Socket Proxy Unrestricted Containerscve-2026-78122-docker-socket-proxy-unrestricted-containersCVE-2026-77781: Perl Unguarded Dynamic Regex Compilationcve-2026-77781-perl-unguarded-dynamic-regex-compilationCVE-2026-75759: Jwt Util Erl Cwe 000 Cve 2026 75759cve-2026-75759-jwt-util-erl-cwe-000-cve-2026-75759CVE-2026-75589: Perl Non Constant Time Signature Comparisoncve-2026-75589-perl-non-constant-time-signature-comparisonCVE-2026-73666: Backstage Hardcoded Dangerous Auth Policycve-2026-73666-backstage-hardcoded-dangerous-auth-policyCVE-2026-73198: Apache Missing Request Read Timeoutcve-2026-73198-apache-missing-request-read-timeoutCVE-2026-73077: Vim Unquoted Command Args Injectioncve-2026-73077-vim-unquoted-command-args-injectionCVE-2026-72889: Net Oauth Unvalidated Signature Method Verifycve-2026-72889-net-oauth-unvalidated-signature-method-verifyCVE-2026-72887: Perl Net Oauth Silent Downgradecve-2026-72887-perl-net-oauth-silent-downgradeCVE-2026-71566: Kubevirt Unauthenticated Ambient Kubeconfig Actioncve-2026-71566-kubevirt-unauthenticated-ambient-kubeconfig-actionCVE-2026-71435: Statamic Antlers Unsanitized Template Outputcve-2026-71435-statamic-antlers-unsanitized-template-outputCVE-2026-67611: Claude Code Action Allowed Bash Toolscve-2026-67611-claude-code-action-allowed-bash-toolsCVE-2026-67610: Claude Code Action Bash Tool Exposurecve-2026-67610-claude-code-action-bash-tool-exposureCVE-2026-66824: Jinja Inline Js Unsafe Jsoncve-2026-66824-jinja-inline-js-unsafe-jsonCVE-2026-66421: Index Html Cwe 79 Cve 2026 66421cve-2026-66421-index-html-cwe-79-cve-2026-66421CVE-2026-63187: Github Actions Untrusted Run Interpolationcve-2026-63187-github-actions-untrusted-run-interpolationCVE-2026-62902: Github Copilot Instructions Missing Agent Scopecve-2026-62902-github-copilot-instructions-missing-agent-scopeCVE-2026-62147: Go Sum Cwe 502 Cve 2026 62147cve-2026-62147-go-sum-cwe-502-cve-2026-6214724 of 182 loaded