gitsafehub
github.com/kossnocorp/chessboard.pro ↗

kossnocorp/chessboard.pro

scanned 2026-08-09 · git 034fc43
3 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets1Vulnerable dependencies121Known OSS vulnerabilities194Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 1 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    pkgs/web/.dev.vars:8
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 121 found · 5 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2026-53512 Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-53512). Fix: Update that package to its patched version.
  • Serious GHSA-xg6x-h9c9-2m83 Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
    pnpm-lock.yaml
    A package you depend on has a known security hole (GHSA-xg6x-h9c9-2m83). Fix: Update that package to its patched version.
  • Serious CVE-2026-25896 fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-25896). Fix: Update that package to its patched version.
  • Serious CVE-2026-25896 fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-25896). Fix: Update that package to its patched version.
  • Serious CVE-2025-55182 next: React Server Components: Pre-authentication remote code execution via unsafe deserialization
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-55182). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-25547 brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-25547). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-3125 opennextjs-cloudflare has SSRF vulnerability via /cdn-cgi/ path normalization bypass
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-3125). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-61928 Better Auth: Unauthenticated API key creation through api-key plugin
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-61928). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45364 Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-45364). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53514 Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-53514). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53516 Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-53516). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53518 @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-53518). Fix: Update that package to its patched version.
  • Worth fixing GHSA-86j7-9j95-vpqj Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
    pnpm-lock.yaml
    A package you depend on has a known security hole (GHSA-86j7-9j95-vpqj). Fix: Update that package to its patched version.
  • Worth fixing GHSA-9h47-pqcx-hjr4 Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
    pnpm-lock.yaml
    A package you depend on has a known security hole (GHSA-9h47-pqcx-hjr4). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qq9h-g4jm-xgf3 Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
    pnpm-lock.yaml
    A package you depend on has a known security hole (GHSA-qq9h-g4jm-xgf3). Fix: Update that package to its patched version.
  • Worth fixing GHSA-x732-6j76-qmhm Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
    pnpm-lock.yaml
    A package you depend on has a known security hole (GHSA-x732-6j76-qmhm). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wxw3-q3m9-c3jr Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
    pnpm-lock.yaml
    A package you depend on has a known security hole (GHSA-wxw3-q3m9-c3jr). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-13466 body-parser: body-parser denial of service
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-13466). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-13149). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-14257 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-14257). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-69152 brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-69152). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33750 brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-33750). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-35209 defu: Prototype pollution via `__proto__` key in defaults argument
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-35209). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-39356 Drizzle ORM has SQL injection via improperly escaped SQL identifiers
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-39356). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-26278 fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion
    pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-26278). Fix: Update that package to its patched version.
… 96 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 194 found · 7 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-pw9m-5jxm-xr6h Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-53512). Fix: Update that package to its patched version.
  • Serious GHSA-xg6x-h9c9-2m83 Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-67337). Fix: Update that package to its patched version.
  • Serious GHSA-m7jm-9gc2-mpf2 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-25896). Fix: Update that package to its patched version.
  • Serious GHSA-m7jm-9gc2-mpf2 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-25896). Fix: Update that package to its patched version.
  • Serious GHSA-9qr9-h5gf-34mp Next.js is vulnerable to RCE in React flight protocol
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious GHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited input
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Serious GHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited input
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Worth fixing GHSA-7h2j-956f-4vf2 @isaacs/brace-expansion has Uncontrolled Resource Consumption
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-25547). Fix: Update that package to its patched version.
  • Worth fixing GHSA-c7mq-gh6q-6q7c opennextjs-cloudflare has SSRF vulnerability via /cdn-cgi/ path normalization bypass
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-6087). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2g4f-4pwh-qvx6 ajv has ReDoS when using `$data` option
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-69873). Fix: Update that package to its patched version.
  • Worth fixing GHSA-7w99-5wm4-3g79 @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-53518). Fix: Update that package to its patched version.
  • Worth fixing GHSA-86j7-9j95-vpqj Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-67333). Fix: Update that package to its patched version.
  • Worth fixing GHSA-99h5-pjcv-gr6v Better Auth: Unauthenticated API key creation through api-key plugin
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-61928). Fix: Update that package to its patched version.
  • Worth fixing GHSA-9h47-pqcx-hjr4 Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-67336). Fix: Update that package to its patched version.
  • Worth fixing GHSA-fmh4-wcc4-5jm3 Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-53514). Fix: Update that package to its patched version.
  • Worth fixing GHSA-g38m-r43w-p2q7 Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-53516). Fix: Update that package to its patched version.
  • Worth fixing GHSA-p6v2-xcpg-h6xw Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-45364). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qq9h-g4jm-xgf3 Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-67327). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wxw3-q3m9-c3jr Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-67335). Fix: Update that package to its patched version.
  • Worth fixing GHSA-x732-6j76-qmhm Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-71399). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wqch-xfxh-vrr4 body-parser is vulnerable to denial of service when url encoding is used
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-13466). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-13149). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f886-m6hf-6m8v brace-expansion: Zero-step sequence causes process hang and memory exhaustion
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-33750). Fix: Update that package to its patched version.
  • Worth fixing GHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-14257). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
    /workdirs/scan-813608ff-2c61-4306-b9ff-f88e34699c5f/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-69152). Fix: Update that package to its patched version.
… 169 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: npm:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.