Packages you depend on that have known security holes (CVEs).
-
Serious CVE-2023-45133 babel: arbitrary code execution
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2023-45133). Fix: Update that package to its patched version.
-
Serious CVE-2025-9287 cipher-base: Cipher-base hash manipulation
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2025-9287). Fix: Update that package to its patched version.
-
Serious CVE-2020-12265 Path Traversal in decompress
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2020-12265). Fix: Update that package to its patched version.
-
Serious GHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
frontend/package-lock.json
A package you depend on has a known security hole (GHSA-vjh7-7g9h-fjfh). Fix: Update that package to its patched version.
-
Serious CVE-2022-1650 eventsource: Exposure of Sensitive Information
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2022-1650). Fix: Update that package to its patched version.
-
Serious CVE-2022-1650 eventsource: Exposure of Sensitive Information
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2022-1650). Fix: Update that package to its patched version.
-
Serious CVE-2025-7783 form-data: Unsafe random function in form-data
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
-
Serious CVE-2021-3918 nodejs-json-schema: Prototype pollution vulnerability
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2021-3918). Fix: Update that package to its patched version.
-
Serious CVE-2022-37601 loader-utils: prototype pollution in function parseQuery in parseQuery.js
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2022-37601). Fix: Update that package to its patched version.
-
Serious CVE-2021-44906 minimist: prototype pollution
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2021-44906). Fix: Update that package to its patched version.
-
Serious CVE-2021-44906 minimist: prototype pollution
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2021-44906). Fix: Update that package to its patched version.
-
Serious CVE-2022-2216 Server-Side Request Forgery in parse-url
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2022-2216). Fix: Update that package to its patched version.
-
Serious CVE-2022-2900 Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2022-2900). Fix: Update that package to its patched version.
-
Serious CVE-2025-6545 pbkdf2: pbkdf2 silently returns predictable key material
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2025-6545). Fix: Update that package to its patched version.
-
Serious CVE-2025-6547 pbkdf2: pbkdf2 silently returns static keys
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2025-6547). Fix: Update that package to its patched version.
-
Serious CVE-2025-9288 sha.js: Missing type checks leading to hash rewind and passing on crafted data
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2025-9288). Fix: Update that package to its patched version.
-
Serious CVE-2026-9277 shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2026-9277). Fix: Update that package to its patched version.
-
Serious CVE-2022-2421 Insufficient validation when decoding a Socket.IO packet
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2022-2421). Fix: Update that package to its patched version.
-
Serious CVE-2022-2421 Insufficient validation when decoding a Socket.IO packet
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2022-2421). Fix: Update that package to its patched version.
-
Serious CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
-
Serious CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
-
Serious CVE-2022-0686 npm-url-parse: Authorization bypass through user-controlled key
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2022-0686). Fix: Update that package to its patched version.
-
Serious CVE-2026-54466 websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2026-54466). Fix: Update that package to its patched version.
-
Serious CVE-2020-28502 nodejs-xmlhttprequest: Code injection through user input to xhr.send
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2020-28502). Fix: Update that package to its patched version.
-
Serious CVE-2021-31597 xmlhttprequest-ssl: SSL certificate validation disabled by default
frontend/package-lock.json
A package you depend on has a known security hole (CVE-2021-31597). Fix: Update that package to its patched version.