Someone shared this scan with you

package-lock.json · 476 dependencies

19

vulnerable versions were reachable from this dependency tree.

1 of them have no fixed release.

  • criticalseroval@1.5.2

    seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization

    fixed in 1.5.3
  • criticalvitest@1.6.1

    When Vitest UI server is listening, arbitrary file can be read and executed

    fixed in 4.1.0
  • highbrace-expansion@1.1.14

    brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

    fixed in 5.0.7
  • highbrace-expansion@1.1.14

    brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash

    fixed in 5.0.8
  • highbrace-expansion@1.1.14

    brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

    fixed in 5.0.9
  • highminimatch@3.0.8

    minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

    fixed in 10.2.3
  • highminimatch@3.0.8

    minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

    fixed in 10.2.1
  • highminimatch@3.0.8

    minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

    fixed in 10.2.3
  • highbrace-expansion@5.0.5

    brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

    fixed in 5.0.7
  • highbrace-expansion@5.0.5

    brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash

    fixed in 5.0.8
  • highbrace-expansion@5.0.5

    brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

    fixed in 5.0.9
  • highbrace-expansion@2.1.0

    brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

    fixed in 5.0.7
  • highbrace-expansion@2.1.0

    brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash

    fixed in 5.0.8
  • highbrace-expansion@2.1.0

    brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

    fixed in 5.0.9
  • highbrowserslist@4.28.2

    Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)

    fixed in 4.28.7
  • highbrowserslist@4.28.2

    Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM

    fixed in 4.28.7
  • highjs-yaml@4.1.1

    js-yaml: YAML merge-key chains can force quadratic CPU consumption

    fixed in 4.3.0
  • highjs-yaml@4.1.1

    JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported

    fixed in 4.3.1
  • highlodash@4.17.23

    lodash vulnerable to Code Injection via `_.template` imports key names

    fixed in 4.18.0
  • highnanoid@3.3.15

    nanoid: non-secure generators can loop indefinitely with negative size

    fixed in 5.1.16
  • highnanoid@3.3.15

    nanoid: custom generators can loop indefinitely when size is zero

    fixed in 5.1.6
  • highpostcss@8.5.16

    PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

    fixed in 8.5.18
  • highundici@7.25.0

    undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

    fixed in 8.9.0
  • highundici@7.25.0

    undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse

    fixed in 8.2.0
  • highundici@7.25.0

    undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent

    fixed in 8.5.0
  • highundici@7.25.0

    undici WebSocket client vulnerable to denial of service via fragment count bypass

    fixed in 8.5.0
  • highvite@5.4.21

    vite: `server.fs.deny` bypass on Windows alternate paths

    fixed in 8.0.16
  • moderatevue-template-compiler@2.7.16

    vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)

    no fix
  • moderateajv@6.12.6

    ajv has ReDoS when using `$data` option

    fixed in 8.18.0
  • moderatebrace-expansion@5.0.5

    brace-expansion: Large numeric range defeats documented `max` DoS protection

    fixed in 5.0.6
  • moderate@xmldom/xmldom@0.9.10

    xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization

    fixed in 0.9.12
  • moderateesbuild@0.21.5

    esbuild enables any website to send any requests to the development server and read the response

    fixed in 0.25.0
  • moderatejs-yaml@4.1.1

    JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

    fixed in 4.2.0
  • moderatelodash@4.17.23

    lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`

    fixed in 4.18.0
  • moderatepostcss@8.5.16

    PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

    fixed in 8.5.23
  • moderateundici@7.25.0

    undici vulnerable to downstream response desynchronization via retry interceptor

    fixed in 8.9.0
  • moderateundici@7.25.0

    undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

    fixed in 8.9.0
  • moderateundici@7.25.0

    undici vulnerable to CRLF Injection via blob-like body 'type' property

    fixed in 8.9.0
  • moderateundici@7.25.0

    undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

    fixed in 8.5.0
  • moderateundici@7.25.0

    undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

    fixed in 8.5.0
  • moderateundici@7.25.0

    undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

    fixed in 8.9.0
  • moderatevite@5.4.21

    Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

    fixed in 8.0.5
  • moderatevite@5.4.21

    launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

    fixed in 8.0.16
  • low@babel/core@7.29.0

    @babel/core: Arbitrary File Read via sourceMappingURL Comment

    fixed in 8.0.0-rc.6
  • lowesbuild@0.28.0

    esbuild allows arbitrary file read when running the development server on Windows

    fixed in 0.28.1
  • lowundici@7.25.0

    undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

    fixed in 8.5.0
  • lowundici@7.25.0

    undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

    fixed in 8.5.0

18 of these can't reach your next install.

Install Safe is an npm registry proxy that strips malicious and vulnerable versions before npm install can reach them — on developer machines, in CI, and from AI agents.

This report holds findings only — never the package.json or lockfile it came from. The link expires in 1 day. To have it deleted sooner, email support@installsafe.io.