Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

kvcache-ai/ktransformers

https://github.com/kvcache-ai/ktransformers · scanned 2026-07-23 19:43 UTC (5 days, 22 hours ago)

626 raw signals (0 security + 626 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 5 days, 22 hours ago · v4 · 606 actionable findings from 1 signal source. 20 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: severity: high × excluding tests × Reset all
Corpus Intelligence Cross-corpus context (cohort percentile, top patterns, fix plan) is shown only on repositories you own. Sign up and connect your repo to view it.
Scan summary Repository scanned at 65.6/100 with 100.0% coverage. It contains 6625 nodes across 30 cross-layer flows, written primarily in mixed languages. Engine surfaced 626 findings — concentrated in security (398), quality (108), dependencies (70). Risk profile is high: 18 critical, 143 high, 280 medium. Recommended next step: open the security layer findings first — that's where the highest-impact wins live.

Showing 142 of 606 actionable findings. 626 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

high System graph security Trivy conf 1.00 CVE-2022-25881: http-cache-semantics 3.8.1 — archive/kt-sft/ktransformers/website/package-lock.json
http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using t…
VulnCve 2022 25881
high System graph security Trivy conf 1.00 CVE-2022-25881: http-cache-semantics 3.8.1 — archive/ktransformers/website/package-lock.json
http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using t…
VulnCve 2022 25881
high System graph security Trivy conf 1.00 CVE-2022-25900: git-clone 0.1.0 — archive/kt-sft/ktransformers/website/package-lock.json
Command injection in git-clone All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git. Package: git-clone Installed: 0.1.0 Fixed in: — Severity: HIGH Fix: No fix version published yet
VulnCve 2022 25900
high System graph security Trivy conf 1.00 CVE-2022-25900: git-clone 0.1.0 — archive/ktransformers/website/package-lock.json
Command injection in git-clone All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git. Package: git-clone Installed: 0.1.0 Fixed in: — Severity: HIGH Fix: No fix version published yet
VulnCve 2022 25900
high System graph security Trivy conf 1.00 CVE-2024-21538: cross-spawn 6.0.5 — archive/kt-sft/ktransformers/website/package-lock.json
cross-spawn: regular expression denial of service Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by craftin…
VulnCve 2024 21538
high System graph security Trivy conf 1.00 CVE-2024-21538: cross-spawn 6.0.5 — archive/ktransformers/website/package-lock.json
cross-spawn: regular expression denial of service Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by craftin…
VulnCve 2024 21538
high System graph security Trivy conf 1.00 CVE-2024-21538: cross-spawn 7.0.3 — archive/kt-sft/ktransformers/website/package-lock.json
cross-spawn: regular expression denial of service Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by craftin…
VulnCve 2024 21538
high System graph security Trivy conf 1.00 CVE-2024-21538: cross-spawn 7.0.3 — archive/ktransformers/website/package-lock.json
cross-spawn: regular expression denial of service Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by craftin…
VulnCve 2024 21538
high System graph security Trivy conf 1.00 CVE-2024-37890: ws 7.5.9 — archive/kt-sft/ktransformers/website/package-lock.json
nodejs-ws: denial of service when handling a request with many HTTP headers ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in [email protected] (e…
VulnCve 2024 37890
high System graph security Trivy conf 1.00 CVE-2024-37890: ws 7.5.9 — archive/ktransformers/website/package-lock.json
nodejs-ws: denial of service when handling a request with many HTTP headers ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in [email protected] (e…
VulnCve 2024 37890
high System graph security Trivy conf 1.00 CVE-2024-39338: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: axios: Server-Side Request Forgery axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs. Package: axios Installed: 1.7.0 Fixed in: 1.7.4 Severity: HIGH Fix: Upgrade axios to 1.7.4
VulnCve 2024 39338
high System graph security Trivy conf 1.00 CVE-2024-39338: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: axios: Server-Side Request Forgery axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs. Package: axios Installed: 1.7.0 Fixed in: 1.7.4 Severity: HIGH Fix: Upgrade axios to 1.7.4
VulnCve 2024 39338
high System graph security Trivy conf 1.00 CVE-2024-4068: braces 2.3.2 — archive/kt-sft/ktransformers/website/package-lock.json
braces: fails to limit the number of characters it can handle The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will…
VulnCve 2024 4068
high System graph security Trivy conf 1.00 CVE-2024-4068: braces 2.3.2 — archive/ktransformers/website/package-lock.json
braces: fails to limit the number of characters it can handle The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will…
VulnCve 2024 4068
high System graph security Trivy conf 1.00 CVE-2024-4068: braces 3.0.2 — archive/kt-sft/ktransformers/website/package-lock.json
braces: fails to limit the number of characters it can handle The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will…
VulnCve 2024 4068
high System graph security Trivy conf 1.00 CVE-2024-4068: braces 3.0.2 — archive/ktransformers/website/package-lock.json
braces: fails to limit the number of characters it can handle The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will…
VulnCve 2024 4068
high System graph security Trivy conf 1.00 CVE-2024-4367: pdfjs-dist 2.6.347 — archive/kt-sft/ktransformers/website/package-lock.json
Mozilla: Arbitrary JavaScript execution in PDF.js A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Package: pdfjs-dist Installed…
VulnCve 2024 4367
high System graph security Trivy conf 1.00 CVE-2024-4367: pdfjs-dist 2.6.347 — archive/ktransformers/website/package-lock.json
Mozilla: Arbitrary JavaScript execution in PDF.js A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Package: pdfjs-dist Installed…
VulnCve 2024 4367
high System graph security Trivy conf 1.00 CVE-2024-4367: pdfjs-dist 3.5.141 — archive/kt-sft/ktransformers/website/package-lock.json
Mozilla: Arbitrary JavaScript execution in PDF.js A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Package: pdfjs-dist Installed…
VulnCve 2024 4367
high System graph security Trivy conf 1.00 CVE-2024-4367: pdfjs-dist 3.5.141 — archive/ktransformers/website/package-lock.json
Mozilla: Arbitrary JavaScript execution in PDF.js A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Package: pdfjs-dist Installed…
VulnCve 2024 4367
high System graph security Trivy conf 1.00 CVE-2024-45296: path-to-regexp 0.1.7 — archive/kt-sft/ktransformers/website/package-lock.json
path-to-regexp: Backtracking regular expressions cause ReDoS path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching run…
VulnCve 2024 45296
high System graph security Trivy conf 1.00 CVE-2024-45296: path-to-regexp 0.1.7 — archive/ktransformers/website/package-lock.json
path-to-regexp: Backtracking regular expressions cause ReDoS path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching run…
VulnCve 2024 45296
high System graph security Trivy conf 1.00 CVE-2024-45590: body-parser 1.20.2 — archive/kt-sft/ktransformers/website/package-lock.json
body-parser: Denial of Service Vulnerability in body-parser body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of request…
VulnCve 2024 45590
high System graph security Trivy conf 1.00 CVE-2024-45590: body-parser 1.20.2 — archive/ktransformers/website/package-lock.json
body-parser: Denial of Service Vulnerability in body-parser body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of request…
VulnCve 2024 45590
high System graph security Trivy conf 1.00 CVE-2024-52011: launch-editor 2.6.1 — archive/kt-sft/ktransformers/website/package-lock.json
launch-editor: vite: launch-editor: Arbitrary command execution via insufficient file argument sanitization launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, …
VulnCve 2024 52011
high System graph security Trivy conf 1.00 CVE-2024-52011: launch-editor 2.6.1 — archive/ktransformers/website/package-lock.json
launch-editor: vite: launch-editor: Arbitrary command execution via insufficient file argument sanitization launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, …
VulnCve 2024 52011
high System graph security Trivy conf 1.00 CVE-2024-52798: path-to-regexp 0.1.7 — archive/kt-sft/ktransformers/website/package-lock.json
path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to bac…
VulnCve 2024 52798
high System graph security Trivy conf 1.00 CVE-2024-52798: path-to-regexp 0.1.7 — archive/ktransformers/website/package-lock.json
path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to bac…
VulnCve 2024 52798
high System graph security Trivy conf 1.00 CVE-2025-25975: parse-git-config 3.0.0 — archive/kt-sft/ktransformers/website/package-lock.json
parse-git-config: Prototype Pollution Vulneralbility in parse-git-config An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function Package: parse-git-config Installed: 3.0.0 Fixed in: — Severity: HIGH Fix: No fix version published yet
VulnCve 2025 25975
high System graph security Trivy conf 1.00 CVE-2025-25975: parse-git-config 3.0.0 — archive/ktransformers/website/package-lock.json
parse-git-config: Prototype Pollution Vulneralbility in parse-git-config An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function Package: parse-git-config Installed: 3.0.0 Fixed in: — Severity: HIGH Fix: No fix version published yet
VulnCve 2025 25975
high System graph security Trivy conf 1.00 CVE-2025-27152: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specifie…
VulnCve 2025 27152
high System graph security Trivy conf 1.00 CVE-2025-27152: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specifie…
VulnCve 2025 27152
high System graph security Trivy conf 1.00 CVE-2025-27597: vue-i18n 9.13.1 — archive/kt-sft/ktransformers/website/package-lock.json
Vue I18n Allows Prototype Pollution in `handleFlatJson` Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.protot…
VulnCve 2025 27597
high System graph security Trivy conf 1.00 CVE-2025-27597: vue-i18n 9.13.1 — archive/ktransformers/website/package-lock.json
Vue I18n Allows Prototype Pollution in `handleFlatJson` Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.protot…
VulnCve 2025 27597
high System graph security Trivy conf 1.00 CVE-2025-58754: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios DoS via lack of data size check Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http …
VulnCve 2025 58754
high System graph security Trivy conf 1.00 CVE-2025-58754: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios DoS via lack of data size check Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http …
VulnCve 2025 58754
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 4.0.0 — archive/kt-sft/ktransformers/website/package-lock.json
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 4.0.0 — archive/ktransformers/website/package-lock.json
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 1.1.11 — archive/kt-sft/ktransformers/website/package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 1.1.11 — archive/ktransformers/website/package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 2.0.1 — archive/kt-sft/ktransformers/website/package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 2.0.1 — archive/ktransformers/website/package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13311: shell-quote 1.8.1 — archive/kt-sft/ktransformers/website/package-lock.json
shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result …
VulnCve 2026 13311
high System graph security Trivy conf 1.00 CVE-2026-13311: shell-quote 1.8.1 — archive/ktransformers/website/package-lock.json
shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result …
VulnCve 2026 13311
high System graph security Trivy conf 1.00 CVE-2026-23745: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure be…
VulnCve 2026 23745
high System graph security Trivy conf 1.00 CVE-2026-23745: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure be…
VulnCve 2026 23745
high System graph security Trivy conf 1.00 CVE-2026-23950: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On c…
VulnCve 2026 23950
high System graph security Trivy conf 1.00 CVE-2026-23950: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On c…
VulnCve 2026 23950
high System graph security Trivy conf 1.00 CVE-2026-24842: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink crea…
VulnCve 2026 24842
high System graph security Trivy conf 1.00 CVE-2026-24842: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink crea…
VulnCve 2026 24842
high System graph security Trivy conf 1.00 CVE-2026-25639: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ a…
VulnCve 2026 25639
high System graph security Trivy conf 1.00 CVE-2026-25639: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ a…
VulnCve 2026 25639
high System graph security Trivy conf 1.00 CVE-2026-26960: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outs…
VulnCve 2026 26960
high System graph security Trivy conf 1.00 CVE-2026-26960: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outs…
VulnCve 2026 26960
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 3.1.2 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 3.1.2 — archive/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 5.1.6 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 5.1.6 — archive/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 3.1.2 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 3.1.2 — archive/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 5.1.6 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 5.1.6 — archive/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 3.1.2 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 3.1.2 — archive/ktransformers/website/package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 5.1.6 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 5.1.6 — archive/ktransformers/website/package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-29786: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: hardlink path traversal via drive-relative linkpath node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables …
VulnCve 2026 29786
high System graph security Trivy conf 1.00 CVE-2026-29786: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: hardlink path traversal via drive-relative linkpath node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables …
VulnCve 2026 29786
high System graph security Trivy conf 1.00 CVE-2026-31802: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
tar: tar: File overwrite via drive-relative symlink traversal node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, …
VulnCve 2026 31802
high System graph security Trivy conf 1.00 CVE-2026-31802: tar 6.2.1 — archive/ktransformers/website/package-lock.json
tar: tar: File overwrite via drive-relative symlink traversal node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, …
VulnCve 2026 31802
high System graph security Trivy conf 1.00 CVE-2026-33671: picomatch 2.3.1 — archive/kt-sft/ktransformers/website/package-lock.json
picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain pattern…
VulnCve 2026 33671
high System graph security Trivy conf 1.00 CVE-2026-33671: picomatch 2.3.1 — archive/ktransformers/website/package-lock.json
picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain pattern…
VulnCve 2026 33671
high System graph security Trivy conf 1.00 CVE-2026-42033: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: HTTP Transport Hijacking via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) s…
VulnCve 2026 42033
high System graph security Trivy conf 1.00 CVE-2026-42033: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: HTTP Transport Hijacking via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) s…
VulnCve 2026 42033
high System graph security Trivy conf 1.00 CVE-2026-42035: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Arbitrary HTTP header injection via prototype pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP …
VulnCve 2026 42035
high System graph security Trivy conf 1.00 CVE-2026-42035: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Arbitrary HTTP header injection via prototype pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP …
VulnCve 2026 42035
high System graph security Trivy conf 1.00 CVE-2026-42043: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: NO_PROXY bypass via crafted URL Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the …
VulnCve 2026 42043
high System graph security Trivy conf 1.00 CVE-2026-42043: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: NO_PROXY bypass via crafted URL Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the …
VulnCve 2026 42043
high System graph security Trivy conf 1.00 CVE-2026-42264: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Prototype pollution allows information disclosure and request manipulation Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the…
VulnCve 2026 42264
high System graph security Trivy conf 1.00 CVE-2026-42264: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Prototype pollution allows information disclosure and request manipulation Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the…
VulnCve 2026 42264
high System graph security Trivy conf 1.00 CVE-2026-44486: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Information disclosure of proxy credentials via HTTP redirects Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent throug…
VulnCve 2026 44486
high System graph security Trivy conf 1.00 CVE-2026-44486: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Information disclosure of proxy credentials via HTTP redirects Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent throug…
VulnCve 2026 44486
high System graph security Trivy conf 1.00 CVE-2026-44487: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Information disclosure of proxy credentials via redirect flows Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct re…
VulnCve 2026 44487
high System graph security Trivy conf 1.00 CVE-2026-44487: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Information disclosure of proxy credentials via redirect flows Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct re…
VulnCve 2026 44487
high System graph security Trivy conf 1.00 CVE-2026-44488: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Denial of Service due to unenforced request and response size limits Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Appli…
VulnCve 2026 44488
high System graph security Trivy conf 1.00 CVE-2026-44488: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Denial of Service due to unenforced request and response size limits Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Appli…
VulnCve 2026 44488
high System graph security Trivy conf 1.00 CVE-2026-44494: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the applicatio…
VulnCve 2026 44494
high System graph security Trivy conf 1.00 CVE-2026-44494: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the applicatio…
VulnCve 2026 44494
high System graph security Trivy conf 1.00 CVE-2026-44495: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Information disclosure due to prototype pollution vulnerability Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same Jav…
VulnCve 2026 44495
high System graph security Trivy conf 1.00 CVE-2026-44495: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Information disclosure due to prototype pollution vulnerability Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same Jav…
VulnCve 2026 44495
high System graph security Trivy conf 1.00 CVE-2026-44496: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF co…
VulnCve 2026 44496
high System graph security Trivy conf 1.00 CVE-2026-44496: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF co…
VulnCve 2026 44496
high System graph security Trivy conf 1.00 CVE-2026-44705: tmp 0.0.33 — archive/kt-sft/ktransformers/website/package-lock.json
tmp is a temporary file and directory creator for node.js. Prior to 0. ... tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the…
VulnCve 2026 44705
high System graph security Trivy conf 1.00 CVE-2026-44705: tmp 0.0.33 — archive/ktransformers/website/package-lock.json
tmp is a temporary file and directory creator for node.js. Prior to 0. ... tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the…
VulnCve 2026 44705
high System graph security Trivy conf 1.00 CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.24.1 — archive/kt-sft/ktransformers/website/package-lock.json
Babel is a compiler for writing next generation JavaScript. From 7.12. ... Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code t…
VulnCve 2026 44728
high System graph security Trivy conf 1.00 CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.24.1 — archive/ktransformers/website/package-lock.json
Babel is a compiler for writing next generation JavaScript. From 7.12. ... Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code t…
VulnCve 2026 44728
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash 4.17.21 — archive/kt-sft/ktransformers/website/package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash 4.17.21 — archive/ktransformers/website/package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash-es 4.17.21 — archive/kt-sft/ktransformers/website/package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash-es 4.17.21 — archive/ktransformers/website/package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4867: path-to-regexp 0.1.7 — archive/kt-sft/ktransformers/website/package-lock.json
path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c o…
VulnCve 2026 4867
high System graph security Trivy conf 1.00 CVE-2026-4867: path-to-regexp 0.1.7 — archive/ktransformers/website/package-lock.json
path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c o…
VulnCve 2026 4867
high System graph security Trivy conf 1.00 CVE-2026-48779: ws 7.5.9 — archive/kt-sft/ktransformers/website/package-lock.json
ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memor…
VulnCve 2026 48779
high System graph security Trivy conf 1.00 CVE-2026-48779: ws 7.5.9 — archive/ktransformers/website/package-lock.json
ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memor…
VulnCve 2026 48779
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 3.14.1 — archive/kt-sft/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 3.14.1 — archive/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 4.1.0 — archive/kt-sft/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 4.1.0 — archive/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59874: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
tar: Node-tar: Denial of Service via malformed tar archive header node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeated…
VulnCve 2026 59874
high System graph security Trivy conf 1.00 CVE-2026-59874: tar 6.2.1 — archive/ktransformers/website/package-lock.json
tar: Node-tar: Denial of Service via malformed tar archive header node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeated…
VulnCve 2026 59874
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — archive/.devcontainer/Dockerfile
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: archive/.devcontainer/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — archive/Dockerfile
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: archive/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — archive/Dockerfile.xpu
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: archive/Dockerfile.xpu
Misconfig
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — archive/kt-sft/Dockerfile
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: archive/kt-sft/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — archive/kt-sft/Dockerfile.xpu
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: archive/kt-sft/Dockerfile.xpu
Misconfig
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — docker/Dockerfile
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: docker/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0017: 'RUN <package-manager> update' instruction alone — archive/Dockerfile
'RUN <package-manager> update' instruction alone The instruction 'RUN <package-manager> update' should always be followed by '<package-manager> install' in the same RUN statement. Rule: DS-0017 Severity: HIGH Target: archive/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0017: 'RUN <package-manager> update' instruction alone — archive/kt-sft/Dockerfile
'RUN <package-manager> update' instruction alone The instruction 'RUN <package-manager> update' should always be followed by '<package-manager> install' in the same RUN statement. Rule: DS-0017 Severity: HIGH Target: archive/kt-sft/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0029: 'apt-get' missing '--no-install-recommends' — archive/Dockerfile.xpu
'apt-get' missing '--no-install-recommends' '--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y wget curl bash git vim ca-certificates binutils cmake g++ && rm -rf /var/lib/apt/lists/*' Rule: DS-0029 Severity: HIGH Target: archiv…
Misconfig
high System graph security Trivy conf 1.00 DS-0029: 'apt-get' missing '--no-install-recommends' — archive/kt-sft/Dockerfile.xpu
'apt-get' missing '--no-install-recommends' '--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y wget curl bash git vim ca-certificates binutils cmake g++ && rm -rf /var/lib/apt/lists/*' Rule: DS-0029 Severity: HIGH Target: archiv…
Misconfig
high System graph security Trivy conf 1.00 GHSA-5c6j-r48x-rmvq: serialize-javascript 4.0.0 — archive/kt-sft/ktransformers/website/package-lock.json
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() ### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` i…
VulnGhsa 5c6j r48x rmvq
high System graph security Trivy conf 1.00 GHSA-5c6j-r48x-rmvq: serialize-javascript 4.0.0 — archive/ktransformers/website/package-lock.json
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() ### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` i…
VulnGhsa 5c6j r48x rmvq
high System graph security Trivy conf 1.00 GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 — archive/kt-sft/ktransformers/website/package-lock.json
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() ### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` i…
VulnGhsa 5c6j r48x rmvq
high System graph security Trivy conf 1.00 GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 — archive/ktransformers/website/package-lock.json
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() ### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` i…
VulnGhsa 5c6j r48x rmvq
high System graph security security conf 1.00 Insecure pattern 'exec_used' in .github/workflows/release-pypi.yml:53
Found a known-risky pattern (exec_used). Review and replace if possible.
.github/workflows/release-pypi.yml:53 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in .github/workflows/release-sglang-kt.yml:48
Found a known-risky pattern (exec_used). Review and replace if possible.
.github/workflows/release-sglang-kt.yml:48 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in .github/workflows/sync-sglang-submodule.yml:49
Found a known-risky pattern (exec_used). Review and replace if possible.
.github/workflows/sync-sglang-submodule.yml:49 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in docker/Dockerfile:270
Found a known-risky pattern (exec_used). Review and replace if possible.
docker/Dockerfile:270 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in install.sh:73
Found a known-risky pattern (exec_used). Review and replace if possible.
install.sh:73 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in kt-kernel/python/__init__.py:80
Found a known-risky pattern (exec_used). Review and replace if possible.
kt-kernel/python/__init__.py:80 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in kt-kernel/python/cli/__init__.py:18
Found a known-risky pattern (exec_used). Review and replace if possible.
kt-kernel/python/cli/__init__.py:18 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in kt-kernel/setup.py:753
Found a known-risky pattern (exec_used). Review and replace if possible.
kt-kernel/setup.py:753 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in ktransformers.py:17
Found a known-risky pattern (exec_used). Review and replace if possible.
ktransformers.py:17 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in setup.py:12
Found a known-risky pattern (exec_used). Review and replace if possible.
setup.py:12 Exec used
high System graph security security conf 1.00 Insecure pattern 'python_os_system' in archive/ktransformers/local_chat.py:161
Found a known-risky pattern (python_os_system). Review and replace if possible.
archive/ktransformers/local_chat.py:161 Python os system
high System graph security security conf 1.00 Insecure pattern 'subprocess_shell_true' in kt-kernel/bench/compare_moe_performance.py:825
Found a known-risky pattern (subprocess_shell_true). Review and replace if possible.
kt-kernel/bench/compare_moe_performance.py:825 Subprocess shell true
high System graph security Semgrep conf 0.70 subprocess shell true — kt-kernel/bench/compare_moe_performance.py:825
Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead. Rule: py…
kt-kernel/bench/compare_moe_performance.py:825 SecurityPython
high System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.0: GHSA-35jp-ww65-95wh
OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-35jp-ww65-95wh (aka CVE-2026-44494). axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` Aliases: CVE-2026-44494 Advisory: …
archive/kt-sft/ktransformers/website/package.json ScaOsvGhsa 35jp ww65 95wh
high System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.0: GHSA-3g43-6gmg-66jw
OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-3g43-6gmg-66jw (aka CVE-2026-44495). axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge Aliases: CVE-2026-4…
archive/kt-sft/ktransformers/website/package.json ScaOsvGhsa 3g43 6gmg 66jw
high System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.0: GHSA-43fc-jf86-j433
OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-43fc-jf86-j433 (aka CVE-2026-25639). Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig Aliases: CVE-2026-25639 Advisory: https://osv.dev/vu…
archive/kt-sft/ktransformers/website/package.json ScaOsvGhsa 43fc jf86 j433
high System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.0: GHSA-4hjh-wcwx-xvwj
OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-4hjh-wcwx-xvwj (aka CVE-2025-58754). Axios is vulnerable to DoS attack through lack of data size check Aliases: CVE-2025-58754 Advisory: https://osv.dev/vulnerabil…
archive/kt-sft/ktransformers/website/package.json ScaOsvGhsa 4hjh wcwx xvwj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 3.14.1: GHSA-52cp-r559-cp3m
OSV.dev reports `js-yaml` at version `3.14.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869). Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. js-yaml: YAM…
archive/kt-sft/ktransformers/website/package-lock.json ScaOsvGhsa 52cp r559 cp3m
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/5a2dcb17-955a-4003-a052-52b5eb857cff/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/5a2dcb17-955a-4003-a052-52b5eb857cff/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.