gitsafehub
github.com/rictic/glowtalk ↗

rictic/glowtalk

scanned 2026-08-14 · git fee7f64
2 of 6 checks flagged a security issue
🟡 Worth a look
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies14Known OSS vulnerabilities15Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 14 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2025-43865 react-router: React Router allows pre-render data spoofing on React-Router framework mode
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2025-43865). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-59057 react-router: @remix-run/router: React Router XSS Vulnerability
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2025-59057). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-21884 react-router: @remix-run/react: React Router SSR XSS in ScrollRestoration
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-21884). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-22029 @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-22029). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34077 react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-34077). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42211 react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-42211). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42342 react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-42342). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-55685 react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-55685). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-68470 react-router: React Router unexpected external redirect
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2025-68470). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-22030 react-router: React Router CSRF in Action/Server Action Request Processing
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-22030). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-40181 react-router: React Router: Open redirect vulnerability via specially crafted URLs
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-40181). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53666 react-router: React Router: Information disclosure via client-side constructor execution
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-53666). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53669 react-router: React Router: Open Redirect vulnerability via backslashes in navigation components
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-53669). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34077 react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling
    glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-34077). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 15 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing GHSA-67mh-4wv8-2f99 esbuild enables any website to send any requests to the development server and read the response
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-2j2x-hqr9-3h42 React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-40181). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2w69-qvjg-hvjx React Router vulnerable to XSS via Open Redirects
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-22029). Fix: Update that package to its patched version.
  • Worth fixing GHSA-337j-9hxr-rhxg React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-53666). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3cgp-3xvw-98x8 React Router has XSS Vulnerability
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2025-59057). Fix: Update that package to its patched version.
  • Worth fixing GHSA-49rj-9fvp-4h2h React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-42211). Fix: Update that package to its patched version.
  • Worth fixing GHSA-8v8x-cx79-35w7 React Router SSR XSS in ScrollRestoration
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-21884). Fix: Update that package to its patched version.
  • Worth fixing GHSA-8x6r-g9mw-2r78 React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-42342). Fix: Update that package to its patched version.
  • Worth fixing GHSA-9jcx-v3wj-wh4m React Router has unexpected external redirect via untrusted paths
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2025-68470). Fix: Update that package to its patched version.
  • Worth fixing GHSA-chx6-hx7r-mcp5 React Router: Unauthenticated Denial of Service via Inefficient Route Matching
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-55685). Fix: Update that package to its patched version.
  • Worth fixing GHSA-cpj6-fhp6-mr6j React Router allows pre-render data spoofing on React-Router framework mode
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2025-43865). Fix: Update that package to its patched version.
  • Worth fixing GHSA-h5cw-625j-3rxh React Router has CSRF issue in Action/Server Action Request Processing
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-22030). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rxv8-25v2-qmq8 React Router vulnerable to Denial of Service via reflected user input in single-fetch
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-34077). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wrjc-x8rr-h8h6 React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-53669). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rxv8-25v2-qmq8 React Router vulnerable to Denial of Service via reflected user input in single-fetch
    /workdirs/scan-56f6887d-b09c-42f9-a4a0-5c10414403fe/glowtalk/static/package-lock.json
    A package you depend on has a known security hole (CVE-2026-34077). Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.