Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

dreamhunter2333/cloudflare_temp_email

https://github.com/dreamhunter2333/cloudflare_temp_email · scanned 2026-07-23 10:38 UTC (5 days, 4 hours ago)

208 raw signals (0 security + 208 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 5 days, 4 hours ago · v5 · last Δ +4.1 (diff) · 199 actionable findings from 1 signal source. 9 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: layer: dependencies × excluding tests × Reset all
Corpus Intelligence Cross-corpus context (cohort percentile, top patterns, fix plan) is shown only on repositories you own. Sign up and connect your repo to view it.
Scan summary Repository scanned at 55.0/100 with 100.0% coverage. It contains 1183 nodes across 30 cross-layer flows, written primarily in mixed languages. Engine surfaced 208 findings — concentrated in security (67), api (51), frontend (25). Risk profile is high: 1 critical, 46 high, 42 medium. Recommended next step: open the security layer findings first — that's where the highest-impact wins live.

Showing 16 of 199 actionable findings. 208 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.1.1: GHSA-3jxr-9vmj-r5cp
OSV.dev reports `brace-expansion` at version `2.1.1` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expansion: DoS via exp…
frontend/pnpm-lock.yaml ScaOsvGhsa 3jxr 9vmj r5cp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 5.0.6: GHSA-3jxr-9vmj-r5cp
OSV.dev reports `brace-expansion` at version `5.0.6` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expansion: DoS via exp…
frontend/pnpm-lock.yaml ScaOsvGhsa 3jxr 9vmj r5cp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency fast-uri 3.1.2: GHSA-4c8g-83qw-93j6
OSV.dev reports `fast-uri` at version `3.1.2` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-4c8g-83qw-93j6 (aka CVE-2026-13676). Note: `fast-uri` is a transitive dependency — pulled in by another package, not declared directly in a manifest. fast-uri vulnerable to host confusion via …
frontend/pnpm-lock.yaml ScaOsvGhsa 4c8g 83qw 93j6
high System graph dependencies dependencies conf 0.90 Vulnerable dependency fast-uri 3.1.2: GHSA-v2hh-gcrm-f6hx
OSV.dev reports `fast-uri` at version `3.1.2` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-v2hh-gcrm-f6hx (aka CVE-2026-16221). Note: `fast-uri` is a transitive dependency — pulled in by another package, not declared directly in a manifest. fast-uri vulnerable to host confusion via …
frontend/pnpm-lock.yaml ScaOsvGhsa v2hh gcrm f6hx
high System graph dependencies dependencies conf 1.00 Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff
OSV.dev reports `vite` at version `5.4.21` (resolved in `vitepress-docs/pnpm-lock.yaml`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571). vite: `server.fs.deny` bypass on Windows alternate paths Aliases: CVE-2026-53571 Advisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff Fix: upgra…
vitepress-docs/pnpm-lock.yaml ScaOsvGhsa fx2h pf6j xcff
high System graph dependencies dependencies conf 0.90 Vulnerable dependency ws 8.19.0: GHSA-96hv-2xvq-fx4p
OSV.dev reports `ws` at version `8.19.0` (resolved in `e2e/package-lock.json`) is affected by GHSA-96hv-2xvq-fx4p (aka CVE-2026-48779). ws: Memory exhaustion DoS from tiny fragments and data chunks Aliases: CVE-2026-48779 Advisory: https://osv.dev/vulnerability/GHSA-96hv-2xvq-fx4p Fix: upgrade `w…
e2e/package.json ScaOsvGhsa 96hv 2xvq fx4p
medium System graph dependencies dependencies conf 0.90 Dependency service-identity is two or more major versions behind
`service-identity` is pinned at `24.2.0` in `smtp_proxy_server/requirements.txt` while the latest release on the pypi registry is `26.1.0` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade…
smtp_proxy_server/requirements.txt FreshnessOutdated
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9
OSV.dev reports `vite` at version `5.4.21` (resolved in `vitepress-docs/pnpm-lock.yaml`) is affected by GHSA-4w7w-66w2-5vf9 (aka CVE-2026-39365). Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling Aliases: CVE-2026-39365 Advisory: https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9…
vitepress-docs/pnpm-lock.yaml ScaOsvGhsa 4w7w 66w2 5vf9
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3
OSV.dev reports `vite` at version `5.4.21` (resolved in `vitepress-docs/pnpm-lock.yaml`) is affected by GHSA-v6wh-96g9-6wx3 (aka CVE-2026-53632). launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows Aliases: CVE-2026-53632 Advisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6…
vitepress-docs/pnpm-lock.yaml ScaOsvGhsa v6wh 96g9 6wx3
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency ws 8.19.0: GHSA-58qx-3vcg-4xpx
OSV.dev reports `ws` at version `8.19.0` (resolved in `e2e/package-lock.json`) is affected by GHSA-58qx-3vcg-4xpx (aka CVE-2026-45736). ws: Uninitialized memory disclosure Aliases: CVE-2026-45736 Advisory: https://osv.dev/vulnerability/GHSA-58qx-3vcg-4xpx Fix: upgrade `ws` past the affected range…
e2e/package.json ScaOsvGhsa 58qx 3vcg 4xpx
low System graph dependencies dependencies conf 0.90 Dependency @unhead/vue is a major version behind
`@unhead/vue` is pinned at `2.1.15` in `frontend/package.json` while the latest release on the npm registry is `3.2.3` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@unhead/vue` to `3…
frontend/package.json FreshnessOutdated
low System graph dependencies dependencies conf 0.40 Dependency @wangeditor/editor-for-vue declares a version newer than the registry latest
`@wangeditor/editor-for-vue` is declared at `5.1.12` in `frontend/package.json`, but the latest release currently visible on the npm registry is `1.0.2`. The declared major version is 4 major version(s) ahead of the registry. This often indicates a typo, a private fork assumption, or an AI-hallucin…
frontend/package.json FreshnessFuture versionAi generated signal
low System graph dependencies dependencies conf 0.90 Dependency vue-router is a major version behind
`vue-router` is pinned at `4.6.4` in `frontend/package.json` while the latest release on the npm registry is `5.2.0` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `vue-router` to `5.2.…
frontend/package.json FreshnessOutdated
low System graph dependencies dependencies conf 1.00 Node manifest has dependencies but no lockfile: pages/package.json
`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely.
pages/package.json LockfileReproducibilityGenerated repo pattern
low System graph dependencies dependencies conf 1.00 Vulnerable dependency dompurify 3.4.11: GHSA-c2j3-45gr-mqc4
OSV.dev reports `dompurify` at version `3.4.11` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-c2j3-45gr-mqc4. DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Advisory: https://osv.dev/vulnerability/GHSA-c2j3-45gr-mqc4 Fix: upgrade `…
frontend/package.json ScaOsvGhsa c2j3 45gr mqc4
low System graph dependencies dependencies conf 0.90 Vulnerable dependency esbuild 0.27.7: GHSA-g7r4-m6w7-qqqr
OSV.dev reports `esbuild` at version `0.27.7` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-g7r4-m6w7-qqqr. Note: `esbuild` is a transitive dependency — pulled in by another package, not declared directly in a manifest. esbuild allows arbitrary file read when running the development …
frontend/pnpm-lock.yaml ScaOsvGhsa g7r4 m6w7 qqqr
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/0bbcb608-3008-4965-b1d0-459b49369765/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/0bbcb608-3008-4965-b1d0-459b49369765/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.