gitsafehub
github.com/elie222/333-marketplace ↗

elie222/333-marketplace

scanned 2026-08-05 · git 9c8b7b2
3 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets2Vulnerable dependencies20Known OSS vulnerabilities105Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 2 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    .env.development:19
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    .env.production:19
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 20 found · 1 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2025-29927 nextjs: Authorization Bypass in Next.js Middleware
    yarn.lock
    A package you depend on has a known security hole (CVE-2025-29927). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-55565 nanoid: nanoid mishandles non-integer values
    yarn.lock
    A package you depend on has a known security hole (CVE-2024-55565). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-51479 next.js: next: authorization bypass in Next.js
    yarn.lock
    A package you depend on has a known security hole (CVE-2024-51479). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-64645 next: Next.js: Server-Side Request Forgery vulnerability
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-64645). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-47831 next.js: Next.js image optimization has Denial of Service condition
    yarn.lock
    A package you depend on has a known security hole (CVE-2024-47831). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-55173 nextjs: Next.js Content Injection Vulnerability for Image Optimization
    yarn.lock
    A package you depend on has a known security hole (CVE-2025-55173). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-57752 nextjs: Next.js Affected by Cache Key Confusion for Image Optimization API Routes
    yarn.lock
    A package you depend on has a known security hole (CVE-2025-57752). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-57822 Next.js Improper Middleware Redirect Handling Leads to SSRF
    yarn.lock
    A package you depend on has a known security hole (CVE-2025-57822). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-59471 next: NextJS Denial of Service in Image Optimizer
    yarn.lock
    A package you depend on has a known security hole (CVE-2025-59471). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-27980 next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-27980). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-29057 next.js: Next.js: HTTP request smuggling in rewrites
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-29057). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44577 Next.js: Next.js: Denial of Service via Image Optimization API
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-44577). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45623 postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-45623). Fix: Update that package to its patched version.
  • Worth fixing GHSA-r28c-9q8g-f849 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    yarn.lock
    A package you depend on has a known security hole (GHSA-r28c-9q8g-f849). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-44270 PostCSS: Improper input validation in PostCSS
    yarn.lock
    A package you depend on has a known security hole (CVE-2023-44270). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-41305 postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-41305). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-69153 postcss: PostCSS: Information disclosure via crafted sourceMappingURL
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-69153). Fix: Update that package to its patched version.
  • Minor CVE-2026-24001 jsdiff: denial of service vulnerability in parsePatch and applyPatch
    yarn.lock
    A package you depend on has a known security hole (CVE-2026-24001). Fix: Update that package to its patched version.
  • Minor CVE-2023-46298 Next.js missing cache-control header may lead to CDN caching empty reply
    yarn.lock
    A package you depend on has a known security hole (CVE-2023-46298). Fix: Update that package to its patched version.
  • Minor CVE-2025-32421 next.js: Next.js Race Condition to Cache Poisoning
    yarn.lock
    A package you depend on has a known security hole (CVE-2025-32421). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 105 found · 8 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2023-45133). Fix: Update that package to its patched version.
  • Serious GHSA-cpq7-6gpm-g9rc cipher-base is missing type checks, leading to hash rewind and passing on crafted data
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-9287). Fix: Update that package to its patched version.
  • Serious GHSA-xwcq-pm8m-c4vf crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2023-46233). Fix: Update that package to its patched version.
  • Serious GHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-f82v-jwr5-mffw Authorization Bypass in Next.js Middleware
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-29927). Fix: Update that package to its patched version.
  • Serious GHSA-h7cp-r72f-jxh6 pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-6545). Fix: Update that package to its patched version.
  • Serious GHSA-v62p-rq8g-8h59 pbkdf2 silently disregards Uint8Array input, returning static keys
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-6547). Fix: Update that package to its patched version.
  • Serious GHSA-95m3-7q98-8xr5 sha.js is missing type checks leading to hash rewind and passing on crafted data
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-9288). Fix: Update that package to its patched version.
  • Worth fixing GHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-27789). Fix: Update that package to its patched version.
  • Worth fixing GHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-27789). Fix: Update that package to its patched version.
  • Worth fixing GHSA-968p-4wvh-cqc8 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-27789). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` option
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-69873). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3g43-6gmg-66jw axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-44495). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3p68-rc4w-qgx5 Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-62718). Fix: Update that package to its patched version.
  • Worth fixing GHSA-43fc-jf86-j433 Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-25639). Fix: Update that package to its patched version.
  • Worth fixing GHSA-5c9x-8gcm-mpgx Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-42034). Fix: Update that package to its patched version.
  • Worth fixing GHSA-62hf-57xw-28j9 Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-42039). Fix: Update that package to its patched version.
  • Worth fixing GHSA-6chq-wfr3-2hj9 Axios: Header Injection via Prototype Pollution
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-42035). Fix: Update that package to its patched version.
  • Worth fixing GHSA-7q8q-rj6j-mhjq Axios: Nested axios option objects can consume polluted prototype values
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-67319). Fix: Update that package to its patched version.
  • Worth fixing GHSA-898c-q2cr-xwhg axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-44490). Fix: Update that package to its patched version.
  • Worth fixing GHSA-fvcv-3m26-pcqx Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-40175). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hfxv-24rg-xrqf Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-44496). Fix: Update that package to its patched version.
  • Worth fixing GHSA-j5f8-grm9-p9fc Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-44486). Fix: Update that package to its patched version.
  • Worth fixing GHSA-jr5f-v2jv-69x6 axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2025-27152). Fix: Update that package to its patched version.
  • Worth fixing GHSA-m7pr-hjqh-92cm Axios: no_proxy bypass via IP alias allows SSRF
    /workdirs/scan-8c1cfd56-a6b7-43d0-9e48-f2e022316244/yarn.lock
    A package you depend on has a known security hole (CVE-2026-42038). Fix: Update that package to its patched version.
… 80 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: npm:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.