Known Vulnerable Dependency: remotion==4.0.242 — 2 advisory(ies): CVE-2026-30120 (Remotion: remote code execution (RCE) vulnerability); CVE-2026-30121 (Remotion: arbitrary file write vulnerability)
- Category
- Supply Chain
- Confidence
- 98% confidence
- Finding
The manifest explicitly pins
remotionto4.0.242, and the finding reports known critical advisories including remote code execution and arbitrary file write. In the context of a skill that converts SRT input into videos and may process attacker-controlled subtitle content during rendering, a vulnerable media/rendering dependency materially increases the risk of host compromise or filesystem tampering.- Content
