StackRadar

excalidash 2026.2.5 Helm chart

unxwaresVerified publisher

Scored 14 Sept 2026

A helm chart for ExcaliDash, A self-hosted dashboard and organizer for Excalidraw with live collaboration features

Version 2026.2.5 6 months agoapp version 0.4.27 0Artifact Hub

excalidash 2026.2.5 deploys 2 container images: zimengxiong/excalidash-backend and zimengxiong/excalidash-frontend. Across them, 221 findings0 critical, 1 high. The highest contribution is GHSA-r5fr-rjxr-66jc in lodash 4.17.23, fixed in 4.18.0.

Radar Score

2,6200152168

221 findings over 2 of 2 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
zimengxiong/excalidash-backend0.4.270124841,282
zimengxiong/excalidash-frontend0.4.270028841,338

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

147 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-cj63-jhhr-wcxvdompurify@3.3.03.3.2
LowALPINE-CVE-2026-56403expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-56404expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-56405expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-56408expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-56406expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-56407expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-56410expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-56411expat@2.7.4-r02.8.2-r0
LowGHSA-rp9w-3fw7-7cwqdompurify@3.3.03.4.7
LowALPINE-CVE-2025-14104util-linux@2.41.2-r02.41.4-r0
LowGHSA-jfc7-64v2-mr8c@sigstore/core@1.1.03.2.1
LowGHSA-3p4h-7m6x-2hcmmulter@2.0.22.2.0
LowALPINE-CVE-2026-45446openssl@3.5.5-r03.5.7-r0
LowALPINE-CVE-2026-7009curl@8.17.0-r18.20.0-r0
LowGHSA-55q2-fjhq-7xh7dompurify@3.3.03.4.13
LowGHSA-4mjr-xmp4-gh2gqs@6.14.16.16.0
LowALPINE-CVE-2026-56412expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-50219expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-56409expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-27171zlib@1.3.1-r21.3.2-r0
LowALPINE-CVE-2026-32777expat@2.7.4-r02.7.5-r0
LowALPINE-CVE-2026-56132expat@2.7.4-r02.8.2-r0
LowALPINE-CVE-2026-40930libpng@1.6.54-r01.6.58-r1
LowALPINE-CVE-2026-42768openssl@3.5.5-r03.5.7-r0
LowALPINE-CVE-2025-14017curl@8.17.0-r18.18.0-r0
LowALPINE-CVE-2026-32778expat@2.7.4-r02.7.5-r0
LowGHSA-cmwh-pvxp-8882dompurify@3.3.03.4.11
LowGHSA-gvmj-g25r-r7wrdompurify@3.3.03.4.8
LowALPINE-CVE-2026-32776expat@2.7.4-r02.7.5-r0
LowALPINE-CVE-2026-6042musl@1.2.5-r211.2.5-r22
LowGHSA-cjmm-f4jc-qw8rdompurify@3.3.03.3.2
LowGHSA-w9m9-85wc-3x92postcss-selector-parser@6.1.06.1.3
LowGHSA-w7fw-mjwx-w883qs@6.14.16.14.2
LowALPINE-CVE-2026-42770openssl@3.5.5-r03.5.7-r0
LowALPINE-CVE-2026-4367libxpm@3.5.17-r03.5.19-r0
LowALPINE-CVE-2026-56131expat@2.7.4-r02.8.2-r0
LowGHSA-v422-hmwv-36x6body-parser@2.2.12.3.0
LowGHSA-v6h2-p8h4-qcjwbrace-expansion@2.0.12.0.2
LowALPINE-CVE-2026-34757libpng@1.6.54-r01.6.57-r0
LowALPINE-CVE-2026-27456util-linux@2.41.2-r02.41.4-r0
LowALPINE-CVE-2026-41080expat@2.7.4-r02.8.1-r0
LowGHSA-qvfw-j98x-7q72multer@2.0.22.3.0
LowGHSA-vpq2-c234-7xj6@tootallnate/once@2.0.02.0.1
LowGHSA-vxr8-fq34-vvx9dompurify@3.3.03.4.9
LowGHSA-c2j3-45gr-mqc4dompurify@3.3.03.4.12
LowGHSA-x4vx-rjvf-j5p4dompurify@3.3.0no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2026.2.5latest6 months ago0.4.2701521682,620

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/unxwares/excalidash.svg)](https://charts.stackradar.io/charts/unxwares/excalidash)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.