Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Malicious Package
lwc-slds-lbc is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
Improper Authentication
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration.
Affected versions of this package are vulnerable to Improper Authentication via the webhook process. An attacker can trigger unauthorized actions and manipulate agent behavior by sending crafted JSON payloads to the endpoint, resulting in forged events with arbitrary sender addresses and message content.
Permissive List of Allowed Inputs
org.webjars.npm:axios is a promise-based HTTP client for the browser and Node.js.
Affected versions of this package are vulnerable to Permissive List of Allowed Inputs in the isLoopback() and isIPv4Loopback() functions of lib/helpers/shouldBypassProxy.js, which require the first IPv4 octet to be 127 and therefore do not recognize 0.0.0.0 as a loopback address. An attacker who controls the request URL or a redirect target can bypass the NO_PROXY policy for local addresses and route requests to http://0.0.0.0:<port>/ through the configured proxy, reaching internal services, cloud IMDS endpoints, or microservice APIs. Exploitation requires the Node HTTP adapter with HTTP_PROXY or HTTPS_PROXY set and NO_PROXY listing local addresses, attacker control over the URL or redirect target, and a proxy able to reach the local destinations.
Recent vulnerabilities disclosed by Snyk
- M
Prototype Pollution in mongo-object (npm)- M
Regular Expression Denial of Service (ReDoS) in angular-resource (npm)- C
Code Execution in expr-eval (npm)- M
Uncaught Exception in ts-deepmerge (npm)- H
Command Injection in degit (npm)
Snyk security
researchers
have disclosed
3501
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.