Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-41242 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fieldsCVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bombCVE-2026-44288 protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequencesCVE-2026-44289 protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decodingCVE-2026-44290 protobufjs: protobufjs: Denial of Service via crafted schemaCVE-2026-44291 protobufjs: protobufjs: Arbitrary Code Execution via prototype pollutionCVE-2026-44293 protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptorsCVE-2026-48712 protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payloadCVE-2026-44288 protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequencesCVE-2026-44292 protobufjs: protobufjs: Data integrity impact due to prototype pollutionCVE-2026-44294 protobufjs: protobufjs: Denial of Service due to unescaped control characters in field namesCVE-2026-45740 protobufjs: protobufjs: Denial of Service via crafted JSON descriptorsCVE-2026-54269 protobufjs: protobufjs-cli: protobufjs: Denial of Service due to name collision with runtime helpersCVE-2026-59877 protobufjs: protobufjs: Denial of Service via crafted .proto schemaGHSA-f88m-g3jw-g9cj sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591CVE-2026-23745 node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archivesCVE-2026-23950 node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race conditionCVE-2026-24842 node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security checkCVE-2026-26960 node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creationCVE-2026-29786 node-tar: hardlink path traversal via drive-relative linkpathCVE-2026-31802 tar: tar: File overwrite via drive-relative symlink traversalCVE-2026-59874 tar: Node-tar: Denial of Service via malformed tar archive headerCVE-2026-53655 node-tar: node-tar: File smuggling due to inconsistent tar archive parsingCVE-2026-59871 node-tar: node-tar: Denial of Service due to incorrect PAX path handlingCVE-2026-59875 node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadataYour dependencies cross-checked against the OSV vulnerability database.
GHSA-xq3m-2v4x-88gg Arbitrary code execution in protobufjsGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-q6x5-8v7m-xcrf protobufjs has overlong UTF-8 decodingGHSA-2pr8-phx7-x9h3 protobuf.js: Denial of service from crafted field names in generated codeGHSA-66ff-xgx4-vchm protobuf.js: Code injection through bytes field defaults in generated toObject codeGHSA-685m-2w69-288q protobuf.js: Denial of service through unbounded protobuf recursionGHSA-75px-5xx7-5xc7 protobuf.js: Code generation gadget after prototype pollutionGHSA-f38q-mgvj-vph7 protobufjs : Schema-derived names can shadow runtime-significant propertiesGHSA-fx83-v9x8-x52w protobuf.js: Prototype injection in generated message constructorsGHSA-j3f2-48v5-ccww protobufjs: Denial of Service via infinite loop in .proto option parsingGHSA-jggg-4jg4-v7c6 protobufjs: Denial of Service via unbounded recursive JSON descriptor expansionGHSA-jvwf-75h9-cwgg protobuf.js: Process-wide denial of service through unsafe option pathsGHSA-q6x5-8v7m-xcrf protobufjs has overlong UTF-8 decodingGHSA-wcpc-wj8m-hjx6 protobufjs: Denial of service through unbounded Any expansion during JSON conversionGHSA-f88m-g3jw-g9cj sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591GHSA-34x7-hfp2-rc4v node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path TraversalGHSA-83g3-92jg-28cx Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar ExtractionGHSA-8qq5-rm4j-mr97 node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path SanitizationGHSA-8x88-c5mf-7j5w node-tar: Negative tar entry size causes infinite loop in archive replaceGHSA-9ppj-qmqm-q256 node-tar Symlink Path Traversal via Drive-Relative LinkpathGHSA-gvwx-54wh-qm9j node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath recordsGHSA-qffp-2rhf-9h96 tar has Hardlink Path Traversal via Drive-Relative LinkpathGHSA-r292-9mhp-454m node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selectionGHSA-r6q2-hw4h-h46w Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFSGHSA-vmf3-w455-68vh node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.