CVE-2026-6636General

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b. Affected is the function Bun.serve of the file buildCache.js of the component API. Performing a manipulation of the argument pathname results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-20: 3Technical Details · 2026-04-20: 204-20
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6636 Path Traversal in p2r3 Convert via Pathname Manipulation in Bun.serve API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6636

    Post summary

    The entry announces CVE-2026-6636, a path traversal flaw in Bun.serve API’s p2r3 Convert function, but offers no proof‑of‑concept, exploit code, or mitigation details.

    0000045
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-6636 A vulnerability was detected in p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b. Affected is the function Bun.serve of the file buildCache.js of the compone… https://www.cve.org/CVERecord?id=CVE-2026-6636 ----- Traducción: CVE-2026-6636 Se … http://infoflow.cloud`

    Post summary

    The post simply alerts that CVE-2026-6636 exists and references the affected function, but offers no PoC, exploit, patch, or substantive technical details.

    0000035
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6636 A vulnerability was detected in p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b. Affected is the function Bun.serve of the file buildCache.js of the compone… https://www.cve.org/CVERecord?id=CVE-2026-6636

    Post summary

    The notice reports the detection of CVE-2026-6636 in p2r3 convert, specifies it affects the Bun.serve function in buildCache.js, and provides a link to the official CVE record, without further details or remediation guidance.

    00000226
    57.2K followersView on X

Explore more