Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
GHSA-7rqj-j65f-68wh Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassGHSA-7rqj-j65f-68wh Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassCVE-2025-66414 Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by defaultCVE-2026-0621 Anthropic's MCP TypeScript SDK has a ReDoS vulnerabilityCVE-2026-25536 @modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leakCVE-2025-69873 ajv: ReDoS via $data referenceCVE-2025-13466 body-parser: body-parser denial of serviceCVE-2026-4926 path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressionsCVE-2026-4923 path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcardsCVE-2025-15284 qs: qs: Denial of Service via improper input validation in array parsingCVE-2026-8723 ### Summary `qs.stringify` throws `TypeError` when called with `arr ...GHSA-xmf8-cvqr-rfgj Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headersGHSA-x445-f3h2-j279 Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created themCVE-2026-44573 next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18nCVE-2026-44574 Next.js: Next.js: Authorization bypass via crafted query parametersCVE-2026-44575 next.js: Next.js: Unauthorized access to protected content via middleware bypassCVE-2026-44578 Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requestsCVE-2026-44579 next.js: Next.js: Denial of Service via crafted POST requests to server actionsCVE-2026-45109 next.js: Next.js: Information disclosure via security fix bypass in middleware with TurbopackCVE-2026-64641 next: Next.js: Denial of Service via crafted requests to App Router with Server ActionsCVE-2026-64642 next: Next.js: Authentication bypass leading to unauthorized accessCVE-2026-64645 next: Next.js: Server-Side Request Forgery vulnerabilityCVE-2026-64649 next: Next.js: Server-Side Request Forgery via malicious host redirection in Server ActionsGHSA-8h8q-6873-q5fj Next.js Vulnerable to Denial of Service with Server ComponentsGHSA-h25m-26qc-wcjf Next.js HTTP request deserialization can lead to DoS when using insecure React Server ComponentsYour dependencies cross-checked against the OSV vulnerability database.
GHSA-7rqj-j65f-68wh Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassGHSA-7rqj-j65f-68wh Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassGHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited inputGHSA-3qcw-2rhx-2726 Turbo: Unexpected local code execution during Yarn Berry detectionGHSA-345p-7cg4-v4c7 @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuseGHSA-8r9q-7v3j-jr4g Anthropic's MCP TypeScript SDK has a ReDoS vulnerabilityGHSA-w48q-cv73-mx4w Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by defaultGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-wqch-xfxh-vrr4 body-parser is vulnerable to denial of service when url encoding is usedGHSA-27v5-c462-wpq7 path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcardsGHSA-j3q9-mxjg-w52f path-to-regexp vulnerable to Denial of Service via sequential optional groupsGHSA-6rw7-vpxm-498p qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustionGHSA-q8mj-m7cp-5q26 qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is setGHSA-x445-f3h2-j279 Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created themGHSA-xmf8-cvqr-rfgj Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headersGHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` optionGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustionGHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashGHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationGHSA-25h7-pfq9-p65f flatted vulnerable to unbounded recursion DoS in parse() revive phaseCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.