HIGH
GO-2026-5039
stdlib: GO-2026-5039
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-5038
stdlib: GO-2026-5038
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-5037
stdlib: GO-2026-5037
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4986
stdlib: GO-2026-4986
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4982
stdlib: GO-2026-4982
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4981
stdlib: GO-2026-4981
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4980
stdlib: GO-2026-4980
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4977
stdlib: GO-2026-4977
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4976
stdlib: GO-2026-4976
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4971
stdlib: GO-2026-4971
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4947
stdlib: GO-2026-4947
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4946
stdlib: GO-2026-4946
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4918
stdlib: GO-2026-4918
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4870
stdlib: GO-2026-4870
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4869
stdlib: GO-2026-4869
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4865
stdlib: GO-2026-4865
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4864
stdlib: GO-2026-4864
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4603
stdlib: GO-2026-4603
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4602
stdlib: GO-2026-4602
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4601
stdlib: GO-2026-4601
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4403
stdlib: GO-2026-4403
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4342
stdlib: GO-2026-4342
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4341
stdlib: GO-2026-4341
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4340
stdlib: GO-2026-4340
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-4337
stdlib: GO-2026-4337
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4175
stdlib: GO-2025-4175
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4155
stdlib: GO-2025-4155
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4015
stdlib: GO-2025-4015
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4014
stdlib: GO-2025-4014
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4013
stdlib: GO-2025-4013
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4012
stdlib: GO-2025-4012
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4011
stdlib: GO-2025-4011
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4010
stdlib: GO-2025-4010
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4009
stdlib: GO-2025-4009
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4008
stdlib: GO-2025-4008
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4007
stdlib: GO-2025-4007
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-4006
stdlib: GO-2025-4006
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-3956
stdlib: GO-2025-3956
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-3849
stdlib: GO-2025-3849
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-3751
stdlib: GO-2025-3751
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-3750
stdlib: GO-2025-3750
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-3563
stdlib: GO-2025-3563
internal/e2e/lite/library/broad_single_…
HIGH
GO-2025-3503
stdlib: GO-2025-3503
internal/e2e/lite/library/broad_single_…
HIGH
GO-2026-5039
stdlib: GO-2026-5039
go.mod
HIGH
GO-2026-5038
stdlib: GO-2026-5038
go.mod
HIGH
GO-2026-5037
stdlib: GO-2026-5037
go.mod
HIGH
GO-2026-4986
stdlib: GO-2026-4986
go.mod
HIGH
GO-2026-4982
stdlib: GO-2026-4982
go.mod
HIGH
GO-2026-4981
stdlib: GO-2026-4981
go.mod
HIGH
GO-2026-4980
stdlib: GO-2026-4980
go.mod
HIGH
GO-2026-4977
stdlib: GO-2026-4977
go.mod
HIGH
GO-2026-4976
stdlib: GO-2026-4976
go.mod
HIGH
GO-2026-4971
stdlib: GO-2026-4971
go.mod
HIGH
GO-2026-4947
stdlib: GO-2026-4947
go.mod
HIGH
GO-2026-4946
stdlib: GO-2026-4946
go.mod
HIGH
GO-2026-4918
stdlib: GO-2026-4918
go.mod
HIGH
GO-2026-4870
stdlib: GO-2026-4870
go.mod
HIGH
GO-2026-4869
stdlib: GO-2026-4869
go.mod
HIGH
GO-2026-4865
stdlib: GO-2026-4865
go.mod
HIGH
GO-2026-4864
stdlib: GO-2026-4864
go.mod
HIGH
GO-2026-4603
stdlib: GO-2026-4603
go.mod
HIGH
GO-2026-4602
stdlib: GO-2026-4602
go.mod
HIGH
GO-2026-4601
stdlib: GO-2026-4601
go.mod
HIGH
GO-2026-4342
stdlib: GO-2026-4342
go.mod
HIGH
GO-2026-4341
stdlib: GO-2026-4341
go.mod
HIGH
GO-2026-4340
stdlib: GO-2026-4340
go.mod
HIGH
GO-2026-4337
stdlib: GO-2026-4337
go.mod
HIGH
GO-2025-4175
stdlib: GO-2025-4175
go.mod
HIGH
GO-2025-4155
stdlib: GO-2025-4155
go.mod
HIGH
GO-2025-4015
stdlib: GO-2025-4015
go.mod
HIGH
GO-2025-4014
stdlib: GO-2025-4014
go.mod
HIGH
GO-2025-4013
stdlib: GO-2025-4013
go.mod
HIGH
GO-2025-4012
stdlib: GO-2025-4012
go.mod
HIGH
GO-2025-4011
stdlib: GO-2025-4011
go.mod
HIGH
GO-2025-4010
stdlib: GO-2025-4010
go.mod
HIGH
GO-2025-4009
stdlib: GO-2025-4009
go.mod
HIGH
GO-2025-4008
stdlib: GO-2025-4008
go.mod
HIGH
GO-2025-4007
stdlib: GO-2025-4007
go.mod
HIGH
GO-2025-4006
stdlib: GO-2025-4006
go.mod
HIGH
GO-2025-3955
stdlib: GO-2025-3955
go.mod
HIGH
GO-2026-5024
golang.org/x/sys: GO-2026-5024
go.mod
HIGH
GO-2026-5030
golang.org/x/net: GO-2026-5030
go.mod
HIGH
GO-2026-5029
golang.org/x/net: GO-2026-5029
go.mod
HIGH
GO-2026-5028
golang.org/x/net: GO-2026-5028
go.mod
HIGH
GO-2026-5027
golang.org/x/net: GO-2026-5027
go.mod
HIGH
GO-2026-5026
golang.org/x/net: GO-2026-5026
go.mod
HIGH
GO-2026-5025
golang.org/x/net: GO-2026-5025
go.mod
HIGH
GO-2026-4918
golang.org/x/net: GO-2026-4918
go.mod
HIGH
GO-2026-5033
golang.org/x/crypto: GO-2026-5033
go.mod
HIGH
GO-2026-5023
golang.org/x/crypto: GO-2026-5023
go.mod
HIGH
GO-2026-5021
golang.org/x/crypto: GO-2026-5021
go.mod
HIGH
GO-2026-5020
golang.org/x/crypto: GO-2026-5020
go.mod
HIGH
GO-2026-5019
golang.org/x/crypto: GO-2026-5019
go.mod
HIGH
GO-2026-5018
golang.org/x/crypto: GO-2026-5018
go.mod
HIGH
GO-2026-5017
golang.org/x/crypto: GO-2026-5017
go.mod
HIGH
GO-2026-5016
golang.org/x/crypto: GO-2026-5016
go.mod
HIGH
GO-2026-5015
golang.org/x/crypto: GO-2026-5015
go.mod
HIGH
GO-2026-5014
golang.org/x/crypto: GO-2026-5014
go.mod
HIGH
GO-2026-5013
golang.org/x/crypto: GO-2026-5013
go.mod
HIGH
JRN009
Secret-like setting is echoed into a password input value
web/src/pages/SetupAuth.tsx:145
HIGH
JRN009
Secret-like setting is echoed into a password input value
web/src/pages/Settings.tsx:1437
HIGH
JRN009
Secret-like setting is echoed into a password input value
web/src/pages/Settings.tsx:195
HIGH
JRN009
Secret-like setting is echoed into a password input value
web/src/pages/ResetPassword.tsx:161
HIGH
JRN009
Secret-like setting is echoed into a password input value
web/src/pages/Register.tsx:104
HIGH
JRN009
Secret-like setting is echoed into a password input value
web/src/pages/Login.tsx:146
HIGH
JRN009
Secret-like setting is echoed into a password input value
web/src/pages/Agents.tsx:4321
HIGH
JRN009
Secret-like setting is echoed into a password input value
web/src/pages/Agents.tsx:2162
MED
SEC046
[SEC046] Client-side open redirect — window.location = server-supplied URL: Assigning win…
web/src/pages/Pricing.tsx:130
MED
SEC046
[SEC046] Client-side open redirect — window.location = server-supplied URL: Assigning win…
web/src/pages/OAuthAuthorize.tsx:44
MED
SEC046
[SEC046] Client-side open redirect — window.location = server-supplied URL: Assigning win…
web/src/pages/Billing.tsx:21
MED
SEC119
[SEC119] World-writable / world-readable file permissions: World-writable files let any l…
pkg/version/update.go:67
MED
SEC107
[SEC107] Weak TLS version requested (TLSv1.0, TLSv1.1, SSLv3, SSLv2): TLS 1.0 and 1.1 wer…
pkg/runtime/proxy/timing_transport.go:147
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
pkg/runtime/proxy/server.go:294
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
internal/local/pairing/server.go:68
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
internal/daemon/oauth_listener.go:36
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
internal/clawvisorcli/shim/clawvisor-pr…:81
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
internal/groupchat/buffer_redis.go:64
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
internal/api/handlers/pairing_store_red…:36
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
internal/api/handlers/extraction_tracke…:44
MED
MINED111
Bare except continues silently
e2e/install/mock_github_server.py:123
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
DKR002
Dockerfile base image has no explicit tag
deploy/Dockerfile:20
MED
DEPCUR-NPM
npm package `@vitejs/plugin-react` is 1 major version(s) behind (5.1.4 -> 6.0.2)
web/package.json
MED
DEPCUR-NPM
npm package `@types/react-dom` is 1 major version(s) behind (18.3.7 -> 19.2.3)
web/package.json
MED
GHSA-2j2x-hqr9-3h42
react-router: GHSA-2j2x-hqr9-3h42
web/package-lock.json
MED
DKR001
Docker final stage has no non-root USER
internal/runtime/isolation/assets/Docke…:1
MED
AGT007
localStorage write failures are swallowed silently
web/src/hooks/useAuth.tsx:10
MED
AIC004
Suspicious implementation file appears unreferenced
internal/runtime/llmproxy/inline_task_r…:1
MED
AIC004
Suspicious implementation file appears unreferenced
internal/clawvisorcli/cmd_auto_update.go:1
MED
AGT015
Remote install command pipes network code directly to a shell
.github/workflows/e2e-install.yml:26
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
web/src/pages/Agents.tsx:794
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
internal/intent/testdata/eval_cases.json:2502
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
internal/mcp/tools_exec.go:160
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
internal/daemon/auto_update.go:94
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
internal/clawvisorcli/cmd_healthcheck.go:21
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
internal/api/handlers/adaptergen.go:189
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
internal/adapters/microsoft/onedrive/ad…:282
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
internal/adapters/dropbox/adapter.go:171
LOW
DEPCUR-NPM
npm package `ws` is minor version(s) behind (^8.19.0 -> 8.21.0)
extensions/clawvisor-webhook/package.js…
LOW
DEPCUR-NPM
npm package `autoprefixer` is minor version(s) behind (10.4.24 -> 10.5.0)
web/package.json
LOW
DEPCUR-NPM
npm package `recharts` is minor version(s) behind (3.7.0 -> 3.8.1)
web/package.json
LOW
DEPCUR-NPM
npm package `@tanstack/react-query` is minor version(s) behind (5.90.21 -> 5.101.0)
web/package.json
LOW
AIC003
Duplicated implementation block across source files
internal/tui/screens/restrictions.go:70
LOW
AIC003
Duplicated implementation block across source files
internal/tui/screens/helpers.go:32
LOW
AIC003
Duplicated implementation block across source files
internal/tui/client/types.go:138
LOW
AIC003
Duplicated implementation block across source files
internal/setup/setup.go:201
LOW
AIC003
Duplicated implementation block across source files
internal/runtime/llmproxy/secret_detect…:118
LOW
AIC003
Duplicated implementation block across source files
internal/runtime/llmproxy/pending_appro…:34
LOW
AIC003
Duplicated implementation block across source files
internal/runtime/llmproxy/inspector/val…:83
LOW
AIC003
Duplicated implementation block across source files
internal/runtime/llmproxy/human_turns.go:142
LOW
AIC003
Duplicated implementation block across source files
internal/runtime/llmproxy/human_turns.go:139
LOW
AIC003
Duplicated implementation block across source files
internal/runtime/llmproxy/forward.go:305
LOW
AIC003
Duplicated implementation block across source files
internal/runtime/llmproxy/approval_body…:381
LOW
AIC003
Duplicated implementation block across source files
internal/runtime/isolation/compose.go:186
LOW
AIC003
Duplicated implementation block across source files
internal/relay/client.go:82
LOW
AIC003
Duplicated implementation block across source files
internal/notify/telegram/polling.go:144
LOW
AIC003
Duplicated implementation block across source files
internal/local/daemon/daemon.go:381
LOW
AIC003
Duplicated implementation block across source files
internal/e2e/lite/library/pivot_mid_exe…:1
LOW
AIC003
Duplicated implementation block across source files
internal/e2e/lite/drivers/codex.go:66
LOW
AIC003
Duplicated implementation block across source files
internal/callback/callback.go:76
LOW
AIC003
Duplicated implementation block across source files
internal/api/handlers/queue.go:36
LOW
AIC003
Duplicated implementation block across source files
internal/api/handlers/onboarding.go:136
LOW
AIC003
Duplicated implementation block across source files
internal/adapters/perplexity/adapter.go:97
LOW
AIC003
Duplicated implementation block across source files
internal/adapters/microsoft/teams/adapt…:7
LOW
AIC003
Duplicated implementation block across source files
internal/adapters/microsoft/outlook/ada…:7
LOW
AIC003
Duplicated implementation block across source files
internal/adapters/microsoft/credential.…:130
LOW
AIC003
Duplicated implementation block across source files
internal/adapters/google/drive/adapter.…:507
LOW
AIC003
Duplicated implementation block across source files
internal/adapters/google/drive/adapter.…:497
LOW
AIC003
Duplicated implementation block across source files
internal/adapters/google/drive/adapter.…:491
LOW
AIC003
Duplicated implementation block across source files
internal/adapters/google/contacts/adapt…:312
LOW
AIC003
Duplicated implementation block across source files
internal/adapters/google/contacts/adapt…:296
LOW
AIC003
Duplicated implementation block across source files
internal/adapters/google/calendar/adapt…:443
LOW
DKC010
Compose service lacks no-new-privileges hardening
deploy/docker-compose.yml:19
LOW
AIC002
Source file name looks like an AI patch artifact
internal/runtime/llmproxy/inline_task_r…:1
LOW
AIC002
Source file name looks like an AI patch artifact
internal/daemon/auto_update.go:1
LOW
AIC002
Source file name looks like an AI patch artifact
internal/clawvisorcli/cmd_auto_update.go:1
LOW
AIC002
Source file name looks like an AI patch artifact
internal/clawvisorcli/cmd_update.go:1
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
web/src/pages/TOTPVerify.tsx:10
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
web/src/pages/SetupAuth.tsx:13
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
web/src/pages/MFAVerify.tsx:42
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
web/src/pages/Login.tsx:31
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
web/src/pages/ForgotPassword.tsx:18
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
web/src/pages/Billing.tsx:55
INFO
MINED058
[MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escapi…
web/src/components/ServiceIcon.tsx:38
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
web/src/hooks/useAuth.tsx:55
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
web/src/App.tsx:33
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
skills/clawvisor/e2e.mjs:216
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
scripts/live-codex-secret-smoke.sh:53
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
internal/clawvisorcli/cmd_tui.go:107
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
pkg/runtime/proxy/certcache.go:143
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
internal/api/middleware/recover.go:21
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
internal/api/handlers/dedup_cache_redis…:27
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
internal/api/handlers/claim_cache_redis…:33
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
internal/api/handlers/async.go:146
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
internal/daemon/keygen.go:79
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
internal/api/handlers/mobileconfig.go:181
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
internal/api/handlers/adaptergen.go:156
INFO
DEPCUR-NPM
npm package `postcss` is patch version(s) behind (8.5.14 -> 8.5.15)
web/package.json
INFO
DEPCUR-NPM
npm package `dompurify` is patch version(s) behind (3.4.0 -> 3.4.8)
web/package.json
INFO
DEPCUR-NPM
npm package `@codemirror/lang-yaml` is patch version(s) behind (6.1.2 -> 6.1.3)
web/package.json