Someone shared this scan with you
package-lock.json · 476 dependencies
19
vulnerable versions were reachable from this dependency tree.
1 of them have no fixed release.
- criticalseroval@1.5.2
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
fixed in 1.5.3 - criticalvitest@1.6.1
When Vitest UI server is listening, arbitrary file can be read and executed
fixed in 4.1.0 - highbrace-expansion@1.1.14
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
fixed in 5.0.7 - highbrace-expansion@1.1.14
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
fixed in 5.0.8 - highbrace-expansion@1.1.14
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
fixed in 5.0.9 - highminimatch@3.0.8
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
fixed in 10.2.3 - highminimatch@3.0.8
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
fixed in 10.2.1 - highminimatch@3.0.8
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
fixed in 10.2.3 - highbrace-expansion@5.0.5
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
fixed in 5.0.7 - highbrace-expansion@5.0.5
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
fixed in 5.0.8 - highbrace-expansion@5.0.5
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
fixed in 5.0.9 - highbrace-expansion@2.1.0
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
fixed in 5.0.7 - highbrace-expansion@2.1.0
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
fixed in 5.0.8 - highbrace-expansion@2.1.0
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
fixed in 5.0.9 - highbrowserslist@4.28.2
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
fixed in 4.28.7 - highbrowserslist@4.28.2
Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
fixed in 4.28.7 - highjs-yaml@4.1.1
js-yaml: YAML merge-key chains can force quadratic CPU consumption
fixed in 4.3.0 - highjs-yaml@4.1.1
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
fixed in 4.3.1 - highlodash@4.17.23
lodash vulnerable to Code Injection via `_.template` imports key names
fixed in 4.18.0 - highnanoid@3.3.15
nanoid: non-secure generators can loop indefinitely with negative size
fixed in 5.1.16 - highnanoid@3.3.15
nanoid: custom generators can loop indefinitely when size is zero
fixed in 5.1.6 - highpostcss@8.5.16
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
fixed in 8.5.18 - highundici@7.25.0
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
fixed in 8.9.0 - highundici@7.25.0
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
fixed in 8.2.0 - highundici@7.25.0
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
fixed in 8.5.0 - highundici@7.25.0
undici WebSocket client vulnerable to denial of service via fragment count bypass
fixed in 8.5.0 - highvite@5.4.21
vite: `server.fs.deny` bypass on Windows alternate paths
fixed in 8.0.16 - moderatevue-template-compiler@2.7.16
vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
no fix - moderateajv@6.12.6
ajv has ReDoS when using `$data` option
fixed in 8.18.0 - moderatebrace-expansion@5.0.5
brace-expansion: Large numeric range defeats documented `max` DoS protection
fixed in 5.0.6 - moderate@xmldom/xmldom@0.9.10
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
fixed in 0.9.12 - moderateesbuild@0.21.5
esbuild enables any website to send any requests to the development server and read the response
fixed in 0.25.0 - moderatejs-yaml@4.1.1
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
fixed in 4.2.0 - moderatelodash@4.17.23
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
fixed in 4.18.0 - moderatepostcss@8.5.16
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
fixed in 8.5.23 - moderateundici@7.25.0
undici vulnerable to downstream response desynchronization via retry interceptor
fixed in 8.9.0 - moderateundici@7.25.0
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
fixed in 8.9.0 - moderateundici@7.25.0
undici vulnerable to CRLF Injection via blob-like body 'type' property
fixed in 8.9.0 - moderateundici@7.25.0
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
fixed in 8.5.0 - moderateundici@7.25.0
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
fixed in 8.5.0 - moderateundici@7.25.0
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
fixed in 8.9.0 - moderatevite@5.4.21
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
fixed in 8.0.5 - moderatevite@5.4.21
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
fixed in 8.0.16 - low@babel/core@7.29.0
@babel/core: Arbitrary File Read via sourceMappingURL Comment
fixed in 8.0.0-rc.6 - lowesbuild@0.28.0
esbuild allows arbitrary file read when running the development server on Windows
fixed in 0.28.1 - lowundici@7.25.0
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
fixed in 8.5.0 - lowundici@7.25.0
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
fixed in 8.5.0
18 of these can't reach your next install.
Install Safe is an npm registry proxy that strips malicious and vulnerable versions before npm install can reach them — on developer machines, in CI, and from AI agents.
This report holds findings only — never the package.json or lockfile it came from. The link expires in 1 day. To have it deleted sooner, email support@installsafe.io.