{"id":"RSEC-2026-0","summary":"Cross-site Request Forgery (CSRF) vulnerability","details":"The widgetframe R package is exposed to a vulnerability due to its use of the Pym.js library version 1.3.1.  This can result in arbitrary javascript code execution.","modified":"2026-02-18T22:30:36.922343Z","published":"2026-02-18T10:30:00Z","upstream":["CVE-2018-1000086"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000086"},{"type":"WEB","url":"https://blog.apps.npr.org/2018/02/15/pym-security-vulnerability.html"},{"type":"WEB","url":"https://github.com/trafficonese/widgetframe/issues/12"},{"type":"WEB","url":"https://github.com/trafficonese/widgetframe/pull/13"}],"affected":[{"package":{"name":"widgetframe","ecosystem":"CRAN","purl":"pkg:cran/widgetframe"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.1.0"}]}],"versions":["0.1.0","0.2.0","0.3.0","0.3.1"],"database_specific":{"source":"https://github.com/RConsortium/r-advisory-database/blob/main/vulns/widgetframe/RSEC-2026-0.yaml"}}],"schema_version":"1.7.3"}