gitsafehub
github.com/higanoneko/syncclipboard ↗

higanoneko/syncclipboard

scanned 2026-08-12 · git 994c36a
1 of 6 checks flagged a security issue
🟡 Worth a look
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies624Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 624 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2025-53015 ImageMagick: ImageMagick unbounded loop
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2025-53015). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-53101 ImageMagick: ImageMagick Stack Buffer Overflow
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2025-53101). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-55004 imagemagick: ImageMagick: heap-buffer overflow
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2025-55004). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-55154 imagemagick: ImageMagick: integer overflows in MNG magnification
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2025-55154). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-55298 ImageMagick: ImageMagick Format String Bug in InterpretImageFilename leads to arbitrary code execution
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2025-55298). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-57803 imagemagick: ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2025-57803). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-66628 ImageMagick: ImageMagick Integer Overflow leading to out of bounds read (32-bit only)
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2025-66628). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-24481 ImageMagick is free and open-source software used for editing and mani ...
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-24481). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-24485 ImageMagick: ImageMagick: Denial of Service via malformed PCD file processing
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-24485). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25794 ImageMagick: ImageMagick: Denial of service and potential arbitrary code execution via integer overflow in image processing
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-25794). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25965 ImageMagick: ImageMagick: Local File Disclosure via Path Traversal
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-25965). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25967 ImageMagick: ImageMagick: Denial of Service via crafted FTXT file
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-25967). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25968 ImageMagick: ImageMagick: Memory corruption via stack buffer overflow when processing an attribute
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-25968). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25985 ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-25985). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25989 ImageMagick: ImageMagick: Denial of Service via crafted SVG file
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-25989). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-28494 ImageMagick: ImageMagick: Arbitrary code execution or denial of service via maliciously crafted kernel strings
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-28494). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-28691 ImageMagick: ImageMagick: Denial of Service via uninitialized pointer dereference in JBIG decoder
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-28691). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-28693 ImageMagick: ImageMagick: Out-of-bounds read or write due to integer overflow in DIB coder
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-28693). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-30929 ImageMagick: stack-based buffer overflow in MagnifyImage
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-30929). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33901 ImageMagick: Magick.NET: ImageMagick: Denial of Service due to heap buffer overflow in MVG decoder
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-33901). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33908 ImageMagick: Magick.NET: ImageMagick: Denial of Service via deeply nested XML file processing
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-33908). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-46520 ImageMagick: ImageMagick: Denial of Service via out-of-bounds write when processing multiple images
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-46520). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-46522 ImageMagick: ImageMagick: Denial of Service via crafted MIFF file
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-46522). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-49218 ImageMagick: ImageMagick: Denial of Service via crafted DCM image with invalid dimensions
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-49218). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53460 ImageMagick: ImageMagick: Denial of Service via missing memory request check
    src/Directory.Packages.props
    A package you depend on has a known security hole (CVE-2026-53460). Fix: Update that package to its patched version.
… 599 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner none found ✓

Your dependencies cross-checked against the OSV vulnerability database.

Nothing found by this check. ✓

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.