CVE-2026-39315 | unjs unhead up to 2.1.12 safe.ts useHeadSafe incomplete blacklist (GHSA-95h2-gj7x-gx9w)
A vulnerability labeled as critical has been found in unjs unhead up to 2.1.12. This issue affects the function useHeadSafe of the file packages/unhead/src/plugins/safe.ts. The manipulation results in incomplete blacklist.
This vulnerability is identified as CVE-2026-39315. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.