Provally CuratedVerified

Provally CVE/1-day Rules

Curated SAST rules generated from CVE and 1-day vulnerability analysis artifacts.

Fetch pack

greprules pack fetch greprules-cve-1day --engine opengrep
curl https://api.greprules.io/api/packs/greprules-cve-1day.tar.gz -o greprules-cve-1day.tar.gz

Included rules

2,424 rules included. Showing 24 loaded rules.
CVE-2026-56697: Missing Host Check Open Redirectcve-2026-56697-missing-host-check-open-redirectCVE-2026-56348: Typeorm Unscoped Private Or Conditioncve-2026-56348-typeorm-unscoped-private-or-conditionCVE-2026-56326: Unchecked Url Pathname Reconstructioncve-2026-56326-unchecked-url-pathname-reconstructionCVE-2026-56317: Innerhtml Array Join Xsscve-2026-56317-innerhtml-array-join-xssCVE-2026-56304: Picklescan Incomplete Blocklistcve-2026-56304-picklescan-incomplete-blocklistCVE-2026-56109: Missing Error Check Parse Cleanupcve-2026-56109-missing-error-check-parse-cleanupCVE-2026-56104: Insecure Session Restore By Idcve-2026-56104-insecure-session-restore-by-idCVE-2026-55886: Html Sanitizer Blocklist By Selectorcve-2026-55886-html-sanitizer-blocklist-by-selectorCVE-2026-55847: Allure Unsanitized Description Htmlcve-2026-55847-allure-unsanitized-description-htmlCVE-2026-55770: Improper Ldap Escape In Filtercve-2026-55770-improper-ldap-escape-in-filterCVE-2026-55660: Decoded Path Traversal Taintcve-2026-55660-decoded-path-traversal-taintCVE-2026-55617: Custom Session Recreate Without Deletecve-2026-55617-custom-session-recreate-without-deleteCVE-2026-55405: Fail Open Escaping Fallbackcve-2026-55405-fail-open-escaping-fallbackCVE-2026-55185: Unbounded Html Tokenization No Early Exitcve-2026-55185-unbounded-html-tokenization-no-early-exitCVE-2026-55091: Flat To Nested Proto Pollutioncve-2026-55091-flat-to-nested-proto-pollutionCVE-2026-54328: Predictable Temp Dir Path Traversalcve-2026-54328-predictable-temp-dir-path-traversalCVE-2026-54317: Missing Strict Filename Validationcve-2026-54317-missing-strict-filename-validationCVE-2026-54306: N8n Typeorm Unintended Or Query Bolacve-2026-54306-n8n-typeorm-unintended-or-query-bolaCVE-2026-54305: N8n Typeorm Unconstrained Personal Projectcve-2026-54305-n8n-typeorm-unconstrained-personal-projectCVE-2026-54304: Typeorm Insecure Or User Bypasscve-2026-54304-typeorm-insecure-or-user-bypassCVE-2026-54301: Project Repository Ts Cwe 79 Cve 2026 54301cve-2026-54301-project-repository-ts-cwe-79-cve-2026-54301CVE-2026-54293: Weak Path Traversal Guard Splitcve-2026-54293-weak-path-traversal-guard-splitCVE-2026-54290: Jwt Jwk Algorithm Confusioncve-2026-54290-jwt-jwk-algorithm-confusionCVE-2026-54288: Hono Jwt Missing Jwk Extractioncve-2026-54288-hono-jwt-missing-jwk-extraction
24 of 2,424 loaded