Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-mj3g-7xcc-x4vh
  • npm/@phun-ky/defaults-deep
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging 31 Jul
  • Fix available
  • Severity - 7.3 (High)
MAL-2026-959
  • npm/format-defaults
Malicious code in format-defaults (npm) 20 Feb
  • No fix available
GHSA-q2x5-4xjx-c6p9
  • npm/@backstage/backend-defaults
Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow` 21 Jan
  • Fix available
  • Severity - 3.5 (Low)
GHSA-rq6q-wr2q-7pgp
  • npm/@backstage/backend-defaults
  • npm/@backstage/plugin-scaffolder-backend
  • npm/@backstage/plugin-scaffolder-node
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions 21 Jan
  • Fix available
  • Severity - 7.1 (High)
GHSA-79h2-v6hh-wq23
  • npm/@ndhoule/defaults
@ndhoule/defaults prototype pollution 06 Feb 2025
  • No fix available
  • Severity - 7.5 (High)
MAL-2022-2691
  • npm/electron-secure-defaults
Malicious code in electron-secure-defaults (npm) 20 Jun 2022
  • No fix available
GHSA-h6xg-rg33-9mf4
  • npm/deep-defaults
deep-defaults vulnerable to prototype pollution 24 May 2022
  • No fix available
  • Severity - 9.8 (Critical)
GHSA-pjxw-22xf-6pwc
  • npm/defaults-deep
Prototype Pollution in defaults-deep 07 Feb 2019
  • No fix available
  • Severity - 9.8 (Critical)
GHSA-cqp5-m4pq-gfgp
  • npm/defaults-deep
Prototype Pollution in defaults-deep 26 Jul 2018
  • Fix available
  • Severity - 8.8 (High)