Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-gjj5-9665-rwrc
  • npm/probe-image-size
probe-image-size: Quadratic-time Denial of Service in the SVG Parser 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-x8mw-p69m-v3mx
  • npm/@fastify/busboy
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-xjh9-v7x6-24jw
  • npm/@fastify/busboy
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-72qq-p3r5-f7wq
  • npm/@a2ui/web_core
@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions 14 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-fj2x-mqqp-3v2w
  • npm/trigger.dev
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values 15 hours ago
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-4672-hwv6-gq62
  • npm/trigger.dev
Trigger.dev: Cross-environment deployment cancel 15 hours ago
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-9q4r-4842-93vw
  • npm/trigger.dev
Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name 15 hours ago
  • Fix available
  • Severity - 7.7 (High)
GHSA-59h8-w5q6-mfmp
  • npm/trigger.dev
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId 15 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-pqxw-g93w-hj9x
  • npm/trigger.dev
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise 15 hours ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-62ch-8vmq-8xm7
  • npm/figlet
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width 15 hours ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-gg6r-gp4c-89hp
  • npm/trigger.dev
Trigger.dev: V1 coordinator default-secret unauth Socket.IO 15 hours ago
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-q567-cr4x-96w4
  • npm/trigger.dev
Trigger.dev: Blind SSRF via alert-channel webhook 15 hours ago
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-pp95-gc86-jq6q
  • npm/trigger.dev
Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR) 15 hours ago
  • Fix available
  • Severity - 7.1 (High)
MAL-2026-17458
  • npm/translate-base-font
Malicious code in translate-base-font (npm) 16 hours ago
  • No fix available
MAL-2026-17459
  • npm/ui-base-colors
Malicious code in ui-base-colors (npm) 16 hours ago
  • No fix available
MAL-2026-17460
  • npm/ui.dist.min.js
Malicious code in ui.dist.min.js (npm) 16 hours ago
  • No fix available